Skip to content
COOEY

EXPOSURES › CVE-2025-43529

CVE-2025-43529

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-12-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-43529 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Apple products affected by unpatched use-after-free vulnerability in WebKit.

Apple iOS, iPadOS, macOS, and other Apple products are compromised due to a use-after-free vulnerability in WebKit, potentially allowing remote code execution. This vulnerability has been actively exploited in the wild. DIB orgs should apply patches immediately to prevent potential remote code execution attacks.

Shame score — Active exploitation in the wild indicates negligence in addressing a critical security flaw.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.