CVE-2025-43529

Published Dec 17, 2025

Last updated 16 days ago

Exploit knownCVSS high 8.8
WebKit
Zero-day
Mobile device

Overview

Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Source
product-security@apple.com
NVD status
Analyzed
Products
safari, ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apple Multiple Products Use-After-Free WebKit Vulnerability
Exploit added on
Dec 15, 2025
Exploit action due
Jan 5, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending
  1. 🚨 [HIGH] Active exploitation detected: CVE-2025-43529 Exploit in the wild confirmed for CVE-2025-43529 (CVSS 8.8). Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability... 🔗 https://t.co/RZBhpWnHFz #ZeroDay #ExploitInWild #CyberSecurity

    @ctiwatchcloud

    11 Apr 2026

    237 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [CYBERSEC] 𝐃𝐚𝐫𝐤𝐒𝐰𝐨𝐫𝐝 𝐢𝐎𝐒 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐋𝐞𝐚𝐤𝐞𝐝, 𝐅𝐒𝐁-𝐋𝐢𝐧𝐤𝐞𝐝 𝐓𝐀𝟒𝟒𝟔 𝐖𝐞𝐚𝐩𝐨𝐧𝐢𝐳𝐞𝐬 𝐈𝐭 𝐖𝐢𝐭𝐡𝐢𝐧 𝐃𝐚𝐲𝐬 An iOS expl

    @DarkForgeNews

    1 Apr 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. "DarkSword" exploit chain, live since Nov 2025, linked 6 flaws: JavaScriptCore (CVE-2025-31277, CVE-2025-43529), dyld PAC bypass (CVE-2026-20700), WebContent sandbox escape (CVE-2025-14174). #cybersecurity

    @bigmacd16684

    23 Mar 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 📌 استغلال جهات تهديد متعددة لحزمة استغلال iOS "DarkSword" التي تستهدف ست ثغرات تستغل جهات تهديد متعددة بشكل نشط حزمة استغلال iOS متطورة تُعرف باسم "DarkSword"، والتي

    @MisbarSec

    20 Mar 2026

    273 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. DarkSword: second iOS exploit kit in a month. 6 flaws, 3 zero-days (CVE-2026-20700, CVE-2025-43529, CVE-2025-14174), full device takeover. Targets iOS 18.4-18.7. Russian group UNC6353 deploying it in Ukraine. Keep iOS updated. https://t.co/i2p7J4bmxA #infosec

    @CybrPulse

    20 Mar 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Exploit chain analysis! CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 https://t.co/FiR5Qs9oIG

    @Hermes_tooll

    15 Mar 2026

    2374 Impressions

    8 Retweets

    41 Likes

    17 Bookmarks

    1 Reply

    0 Quotes

  7. Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://t.co/Xvnp94lKVC

    @Hermes_tooll

    6 Mar 2026

    4652 Impressions

    8 Retweets

    40 Likes

    35 Bookmarks

    0 Replies

    0 Quotes

  8. https://t.co/bMrWsTYsJ8 🔥 PS5 - CVE-2025-43529: UAF confirmed, ROP gadgets found ✅ Reproducible UAF (10 objects, pattern 1/2) ✅ Base libkernel: 0x0823ef8000 ✅ ROP gadgets: pop rdi/rsi/rdx/rax, syscall ✅ Socketpair thread sync functional ✅ Tests T-001 to T-011 pa

    @marcchoc934

    2 Mar 2026

    6334 Impressions

    12 Retweets

    94 Likes

    11 Bookmarks

    6 Replies

    0 Quotes

  9. https://t.co/Cra4E2RB7u 🔥 PS5 - CVE-2025-43529: UAF confirmed, ROP gadgets found ✅ Reproducible UAF (10 objects, pattern 1/2) ✅ Base libkernel: 0x0823ef8000 ✅ ROP gadgets: pop rdi/rsi/rdx/rax, syscall ✅ Socketpair thread sync functional ✅ Tests T-001 to T-011 pa

    @marcchoc934

    2 Mar 2026

    47 Impressions

    1 Retweet

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  10. https://t.co/ZqIwr5ukVa CVE-2025-43529: A use-after-free CVE-2025-14174: An out-of-bounds PARTAIL

    @K1llah03z

    2 Mar 2026

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. New iPhone patches just dropped - lots of fixes including a zero-day malware implant vulnerability that’s already being exploited. CVE-2025-14174 and CVE-2025-43529 are the in-the-wild RCE holes. You’re looking for version 26.3 *after* the update. Enjoy! https://t.co/CArVRA

    @duckblog

    12 Feb 2026

    181 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  12. I hope one day new PS4 webkit exploit on firmware 10.00 and higher finally see a day to abolish PS Vue and BD-JB Example vulnerability that missed on : CVE-2025-14174 CVE-2025-43529

    @MHasyimy

    7 Feb 2026

    174 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Top 5 Trending CVEs: 1 - CVE-2026-21509 2 - CVE-2026-22812 3 - CVE-2026-0755 4 - CVE-2025-43529 5 - CVE-2026-1281 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    2 Feb 2026

    192 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. A carefully structured, tiered root cause analysis for CVE-2025-43529 (JSC UAF). Spent quite some time refining the structure to make the reasoning explicit and readable. Shoutout to @jir4vv1t for his detailed analysis and exploit. https://t.co/nGiwxIv2aM

    @bjrjk

    1 Feb 2026

    6046 Impressions

    27 Retweets

    100 Likes

    45 Bookmarks

    0 Replies

    0 Quotes

  15. Top 5 Trending CVEs: 1 - CVE-2025-43529 2 - CVE-2026-1281 3 - CVE-2026-24858 4 - CVE-2024-12084 5 - CVE-2026-24061 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Feb 2026

    187 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Top 5 Trending CVEs: 1 - CVE-2025-43529 2 - CVE-2026-24858 3 - CVE-2025-8088 4 - CVE-2025-15467 5 - CVE-2025-23049 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 Jan 2026

    137 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://t.co/NgXP3RfzuE https://t.co/ZcGzBe18Tk

    @ZeeJailbreak

    28 Jan 2026

    4053 Impressions

    10 Retweets

    49 Likes

    15 Bookmarks

    0 Replies

    0 Quotes

  18. PS4 homebrew community should take a look at CVE-2025-43529(new high severity webkit bug), PS Vue is a fuss so much need backup-restore for not jailbroken, and already jailbroken using bd-jb or pppwn can just install PS Vue retail .pkg, but still need psn activated profile.

    @MHasyimy

    27 Jan 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. This exploit code for CVE-2025-43529 and CVE-2025-14174 has been publicly available on GitHub for two weeks, yet VT still shows 0 detections—pretty interesting. https://t.co/BpdrvbpyyS https://t.co/yfZfqchL7C

    @jq0904

    27 Jan 2026

    4962 Impressions

    12 Retweets

    71 Likes

    36 Bookmarks

    2 Replies

    0 Quotes

  20. 🚨 January Linux Patch Wednesday: 918 vulns fixed (616 kernel), 3 exploited (telnetd CVE-2026-24061, Safari CVE-2025-43529, Chromium CVE-2025-14174) + 97 with public exploits. #LinuxPatchWednesday #Linux #Vulristics ➡️ https://t.co/bxPByH2r6f https://t.co/35uge0Gkbg

    @leonov_av

    24 Jan 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🧵 Exploit chain analysis! CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) leads to iOS Safari compromise. 🔥 #Exploit #Web #iOS #CyberSecurity https://t.co/6Zs107sM6s

    @TheExploitLab

    24 Jan 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB): https://t.co/aJog2aUPA7 Vulnerable: iOS ≤26.1 (incl. 17.x–26.1) Patched: iOS 26.2+ Tested on iPhone 11 Pro Max / iOS 26.1 – expect crashes galore! (GC races + PAC issues)

    @hermes_tool1

    24 Jan 2026

    5762 Impressions

    11 Retweets

    93 Likes

    39 Bookmarks

    2 Replies

    0 Quotes

  23. Top 5 Trending CVEs: 1 - CVE-2025-54957 2 - CVE-2026-21962 3 - CVE-2025-43529 4 - CVE-2026-0629 5 - CVE-2017-9506 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 Jan 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 Critical iOS/iPadOS WebKit Zero-Days Put iPhones at Risk of Silent Takeover — Patch Now Apple confirmed two WebKit vulnerabilities (CVE-2025-43529, CVE-2025-14174) that can enable “no warning” compromise through malicious web content, potentially exposing passwords and

    @ThreatSynop

    20 Jan 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Ocak 2026 itibarıyla gündemde olan CVE-2025-43529 ve CVE-2025-14174 kodlu açıklar, "paralı casus yazılımlar" (Pegasus vb.) tarafından iPhone kullanıcılarını hedef almak için kullanılan oldukça tehlikeli iki güvenlik açığıdır. İşte bu saldırı sürecinin ad

    @haydar_beklemez

    20 Jan 2026

    15 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  26. iOS Exploit Chain PoC Alert! @zeroxjf dropped analysis + PoC for CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB): https://t.co/hrWK1DEJHg Vulnerable: iOS ≤26.1 (incl. 17.x–26.1) Patched: iOS 26.2+ Tested on iPhone 11 Pro Max / iOS 26.1 – expect crashes galore! (

    @ZeeJailbreak

    20 Jan 2026

    19994 Impressions

    46 Retweets

    248 Likes

    128 Bookmarks

    11 Replies

    1 Quote

  27. 苹果最近又爆了两个漏洞 分别是 CVE-2025-43529 和 CVE-2025-14174 最近怎么回事,苹果老出漏洞 https://t.co/qsyxRj7XGe

    @annitoBtc

    19 Jan 2026

    488 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  28. Exploit chain analysis: CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB). Targets iOS Safari. Deep dive into the bugs & exploitation. https://t.co/aJog2aUPA7 #exploit #infosec #iOS #webkit #browsersecurity

    @hermes_tool1

    18 Jan 2026

    2686 Impressions

    9 Retweets

    55 Likes

    30 Bookmarks

    0 Replies

    0 Quotes

  29. 🔓 Exploit chain analysis: CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB). Targets iOS Safari. Deep dive into the bugs & exploitation. #exploit #infosec #iOS #webkit #browsersecurity https://t.co/JkaJJyE9i3

    @TheExploitLab

    16 Jan 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. تحليل سلسلة استغلال تجمع بين CVE-2025-43529 (ثغرة Use-After-Free في WebKit) وCVE-2025-14174 (وصول خارج الحدود في ANGLE) لاستهداف Safari على iOS #الأمن_السيبراني #iOS #WebKit https://t.co/Sk9nqZw4mB

    @fad_777

    15 Jan 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CISA has added CVE-2025-43529 to its Known Exploited Vulnerabilities catalog, highlighting a critical use-after-free vulnerability in Apple’s WebKit component. This flaw affects multiple Apple operating systems, including iOS, iPadOS, macOS, and potentially other products that

    @ox0ffff

    12 Jan 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🍎 CVE-2025-43529 — in-the-wild WebKit 0-day now has public exploit Apple: “extremely sophisticated attack against specific targeted individuals” discovered by Google TAG. WebKit DFG JIT UAF → addrof/fakeobj primitives writeup + PoC: https://t.co/XLQ4cC6hzS #itw #web

    @Wh1teCoon

    7 Jan 2026

    188 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  33. iOS 26.2 and iPadOS 26.2, along with a security advisory that includes fixes for WebKit vulnerabilities. One bug in the DFG JIT compiler (CVE-2025-43529) s https://t.co/NWZUmUVoRH TELEGRAM FOR BUSSINES : https://t.co/VfmhipXTwz

    @minacrissDev_

    6 Jan 2026

    4244 Impressions

    6 Retweets

    32 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 Apple Patches Two Actively Exploited WebKit Zero-Days Linked to “Sophisticated” Targeted Attacks Apple shipped emergency fixes for two WebKit zero-days (CVE-2025-43529, CVE-2025-14174) after reports they were used in “extremely sophisticated” attacks against specific

    @ThreatSynop

    21 Dec 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨📱 Apple WebKit zero-days exploited (CVE-2025-43529 / CVE-2025-14174). Update iOS/iPadOS/macOS/Safari now + enable auto-updates. #MobileSecurity #InfoSec Source: https://t.co/qCRP5isyXm https://t.co/6De04xrSal

    @SecureComputer0

    20 Dec 2025

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Critical security update for #Fedora 43: webkitgtk 2.50.4 addresses multiple vulnerabilities including CVE-2025-43529 (use-after-free) and several process crash CVEs. Read more: 👉 https://t.co/NJkSuQFRp4 #Security https://t.co/yjOFlmNhkH

    @Cezar_H_Linux

    19 Dec 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨Chrome & WebKit Zero-Days Hit 3.4 Billion Users This Week Google and Apple coordinated emergency patches for multiple zero-days already exploited in "sophisticated attacks." CVE-2025-14174 (ANGLE out-of-bounds) and CVE-2025-43529 (WebKit memory corruption) credited to Go

    @the_c_protocol

    18 Dec 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. webkit2gtk affected by a Use-After-Free vulnerability (DEBIAN-CVE-2025-43529). Processing malicious content can lead to memory corruption. Monitor for official updates. https://t.co/tEEpDBq4Ae

    @pulsepatchio

    18 Dec 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. WebKit UAF (CVE-2025-43529) JSC DFG JIT missed Phi-merged youngsters during Escape Analysis, thereby allowing to GC an object with a live reference. To exploit: convert UAF to a type confusion, structure mismatch, ARW primitive (eg. synthetic butterfly pointer) @alisaesage htt

    @zerodaytraining

    18 Dec 2025

    3154 Impressions

    8 Retweets

    61 Likes

    29 Bookmarks

    1 Reply

    0 Quotes

  40. WebKit UAF (CVE-2025-43529) JSC DFG JIT missed Phi-sourced youngsters during Escape Analysis, thereby allowing to GC an object with a live reference. To exploit: convert UAF to a type confusion, structure mismatch, ARW primitive (eg. synthetic butterfly pointer) @alisaesage ht

    @zerodaytraining

    18 Dec 2025

    425 Impressions

    1 Retweet

    10 Likes

    1 Bookmark

    1 Reply

    1 Quote

  41. [CVE-2025-43529: HIGH] Critical use-after-free issue fixed in Apple updates for watchOS, Safari, iOS, iPadOS, macOS, visionOS, and tvOS. Processing malicious web content may lead to arbitrary code execution.#cve,CVE-2025-43529,#cybersecurity https://t.co/H6Rk215Pp4 https://t.co/2

    @CveFindCom

    17 Dec 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. devs here we go: Apple zero-day 🚨 CVE-2025-43529 is a WebKit use-after-free actively exploited in the wild. Affects iOS, iPadOS, macOS, Safari, and any app using WebKit. Malicious web content can trigger memory corruption with no extra user interaction, potentially

    @paramdhagia

    17 Dec 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Apple zero-day 🚨 CVE-2025-43529 is a WebKit use-after-free actively exploited in the wild. Affects iOS, iPadOS, macOS, Safari, and any app using WebKit. Malicious web content can trigger memory corruption with no extra user interaction, potentially leading to code https:/

    @paramdhagia

    16 Dec 2025

    139 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  44. This issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web https:

    @minacrissDev_

    16 Dec 2025

    273 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. iOS 26.2 Security Fixes in iOS 26.2 and iPadOS 26.2 WebKit (multiple fixes, including two actively exploited zero-days) - CVE-2025-43529: Use-after-free issue - Malicious web content could lead to arbitrary code execution; actively exploited in targeted attacks. -

    @0xSoKno

    16 Dec 2025

    211 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにGladinet CentreStack and TriofoxのCVE-2025-14611とApple WebKitのCVE-2025-43529を追加。対処期限は通常の1/5。ランサムウェアによる悪

    @__kokumoto

    15 Dec 2025

    833 Impressions

    0 Retweets

    7 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  47. Big updates today: - Apple rushes patches for two exploited WebKit zero-days (CVE-2025-14174 & CVE-2025-43529) tied to a sophisticated Chrome flaw impacting iOS, macOS, Safari & more. Update now! - Rogue Chrome extension with "Featured" badge & 6M users caught spyin

    @ImperialTechSvc

    15 Dec 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🛡️ We added Gladinet & Apple vulnerabilities CVE-2025-14611 & CVE-2025-43529 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/BXihRl42AI

    @CISACyber

    15 Dec 2025

    5685 Impressions

    18 Retweets

    42 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  49. Apple lança atualizações urgentes para corrigir duas zero-days usadas em ataques sofisticados: as falhas CVE-2025-43529 e CVE-2025-14174 afetam o WebKit em iPhones e iPads, exploradas para espionagem direcionada, exigindo atualização imediata dos usuários. https://t.co/ISp0

    @caveiratech

    15 Dec 2025

    43 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Warning: Actively exploited vulnerabilities in #Apple WebKit. CVE-2025-14174 and CVE-2025-43529. Exploitation could lead to arbitrary code execution via malicious web content! Check for the latest updates! #Patch #Patch #Patch More info: https://t.co/CgfPxbCZ4j

    @CCBalert

    15 Dec 2025

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations