Junglewise Threat Intelligence

CVE-2025-43213: Apple Safari and OS memory handling vulnerability in Web Content

CVE-2025-43213 · Severity: medium · CVSS 6.5 · Published 2025-07-30

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

Apple Safari and various Apple operating systems are affected by a memory handling issue when processing web content. An attacker could create a malicious website that, when visited, causes the browser or device to crash unexpectedly. This can disrupt operations and lead to a denial of service for the user.

Technical details

A memory handling vulnerability (classified as CWE-119/CWE-120) exists in Apple's web processing components. The issue is triggered when Safari or the underlying OS processes maliciously crafted web content, leading to an unexpected application crash or denial of service. The vulnerability is reachable over the network and requires minimal user interaction (visiting a website). Apple addressed the issue by improving memory handling in Safari 18.6 and corresponding OS updates. Red Hat has also identified impact in various Enterprise Linux versions that utilize affected components.

Affected products

  • Apple Safari Before 18.6
  • Apple iOS and iPadOS Before 18.6
  • Apple macOS Sequoia Before 15.6
  • Apple tvOS Before 18.6
  • Apple visionOS Before 2.6
  • Apple watchOS Before 11.6
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2025-07-30: advisory: Initial disclosure by Apple and NVD publication

References

Related threats