EXPOSURES › CVE-2025-43529
CVE-2025-43529
HIGH ⌖ ON CISA KEV · EXPLOITEDApple products affected by unpatched use-after-free vulnerability in WebKit.
Apple iOS, iPadOS, macOS, and other Apple products are compromised due to a use-after-free vulnerability in WebKit, potentially allowing remote code execution. This vulnerability has been actively exploited in the wild. DIB orgs should apply patches immediately to prevent potential remote code execution attacks.
Shame score — Active exploitation in the wild indicates negligence in addressing a critical security flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.