Junglewise Threat Intelligence

CVE-2025-43441: Apple WebKit memory corruption in web content processing

CVE-2025-43441 · Severity: medium · CVSS 4.3 · Published 2025-11-04

Technologies: Red Hat Enterprise Linux, Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple Visionos, Apple iPadOS. Vendors: Red Hat, Apple.

Executive brief

A memory handling issue exists in Apple's web processing engine used across iPhones, iPads, and Macs. If a user visits a specially crafted website, the browser or system process may crash unexpectedly. This primarily impacts the reliability and availability of the device's web-related services.

Technical details

A memory handling vulnerability (classified as CWE-119/CWE-120) exists in the components responsible for processing web content across multiple Apple operating systems and Red Hat Enterprise Linux. The root cause is improper memory handling when parsing maliciously crafted web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage, leading to an unexpected process crash (Denial of Service). While CISA-ADP rates this at 4.3 (Medium), Red Hat's assessment suggests a higher potential impact. The issue has been addressed in Safari 26.1, iOS/iPadOS 18.7.2, and other platform updates through improved memory management.

Affected products

  • Apple iOS Before 18.7.2, 26.1
  • Apple iPadOS Before 18.7.2, 26.1
  • Apple Safari Before 26.1
  • Apple macOS Tahoe Before 26.1
  • Apple tvOS Before 26.1
  • Apple visionOS Before 26.1
  • Red Hat Enterprise Linux 8, 9

Timeline

  • 2025-11-04: disclosed: Initial publication date

References

Related threats