Junglewise Threat Intelligence

CVE-2025-43214: Apple Safari and OS memory corruption via malicious web content

CVE-2025-43214 · Severity: medium · CVSS 6.5 · Published 2025-07-30

Technologies: Apple Tvos, Apple macOS, Apple Safari, Red Hat Enterprise Linux, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple, Red Hat.

Executive brief

Apple has released security updates to address a memory handling issue across its major operating systems and the Safari web browser. If a user visits a specially crafted, malicious website, the browser or device may experience an unexpected crash. This could lead to a temporary disruption of service or loss of unsaved work for users on affected iPhones, iPads, Macs, and Apple Watches.

Technical details

A memory handling vulnerability (classified as CWE-119/CWE-120) exists in Apple's WebKit-based components and various operating systems. The flaw is triggered when the system processes maliciously crafted web content, leading to improper restriction of operations within the bounds of a memory buffer. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage, resulting in an unexpected application or system crash (Denial of Service). Apple addressed the issue with improved memory handling in Safari 18.6, iOS/iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, and watchOS 11.6. Red Hat has also identified impact on certain Enterprise Linux versions.

Affected products

  • Apple Safari Before 18.6
  • Apple iOS and iPadOS Before 18.6
  • Apple macOS Sequoia Before 15.6
  • Apple tvOS Before 18.6
  • Apple visionOS Before 2.6
  • Apple watchOS Before 11.6
  • Red Hat Enterprise Linux 8, 7 ELS

Timeline

  • 2025-07-30: advisory
  • 2025-07-30: patched

References

Related threats