Junglewise Threat Intelligence

CVE-2025-43433: Apple and Red Hat memory corruption in web content processing

CVE-2025-43433 · Severity: high · CVSS 8.8 · Published 2025-11-04

Technologies: Apple Visionos, Apple Iphone Os, Apple watchOS, Apple Safari, Red Hat Enterprise Linux Server, Apple macOS Tahoe, Apple iPadOS, Apple Tvos. Vendors: Apple, Red Hat.

Executive brief

A memory corruption vulnerability exists in Apple's web processing engine, affecting Safari and various Apple operating systems including iOS, macOS, and watchOS. An attacker could exploit this by tricking a user into visiting a malicious website, potentially leading to unauthorized access to data or system instability. This issue also impacts certain Red Hat Enterprise Linux environments that utilize related web components.

Technical details

This vulnerability is classified as an out-of-bounds write (CWE-787) or buffer overflow (CWE-120) resulting from improper memory handling when processing web content. The flaw exists in the web rendering components used across Apple's ecosystem (Safari, iOS, macOS, etc.) and has been identified in Red Hat Enterprise Linux packages. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to process specially crafted web content (e.g., visiting a malicious website). Successful exploitation could lead to memory corruption and potentially arbitrary code execution. The issue has been addressed in Safari 26.1, iOS/iPadOS 18.7.2 and 26.1, and corresponding updates for macOS, tvOS, visionOS, and watchOS.

Affected products

  • Apple Safari before 26.1
  • Apple iOS before 18.7.2, before 26.1
  • Apple iPadOS before 18.7.2, before 26.1
  • Apple macOS Tahoe before 26.1
  • Apple tvOS before 26.1
  • Apple visionOS before 26.1
  • Apple watchOS before 26.1
  • Red Hat Enterprise Linux Server 7, 8, 9

Timeline

  • 2025-11-04: advisory: Initial NVD publication date

References

Related threats