Junglewise Threat Intelligence

CVE-2025-43368: Apple Safari and OS use-after-free in web content processing

CVE-2025-43368 · Severity: medium · CVSS 4.3 · Published 2025-09-15

Technologies: Apple macOS, Apple Safari, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

A memory management vulnerability exists in Apple's Safari web browser and operating systems including iOS and macOS. If a user visits a website containing specifically crafted malicious content, it could cause the Safari browser to crash unexpectedly. This impact is primarily limited to service disruption (denial of service) on the affected device.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in Safari and the underlying operating systems (iOS, iPadOS, and macOS). The flaw is rooted in improper memory management during the processing of web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted webpage, which triggers the memory corruption. Successful exploitation results in an application crash (denial of service). Apple addressed the issue in version 26 of the affected products by implementing improved memory management logic.

Affected products

  • Apple Safari before 26
  • Apple iOS before 26
  • Apple iPadOS before 26
  • Apple macOS Tahoe before 26

Timeline

  • 2025-09-15: disclosed
  • 2025-09-15: patched
  • 2025-09-15: advisory

References

Related threats