Vulnerability Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | < 26.0 |
| Apple | Ipados | < 26.0 |
| Apple | Iphone Os | < 26.0 |
| Apple | Macos | < 26.0 |
| Apple | Tvos | < 26.0 |
| Apple | Visionos | < 26.0 |
| Apple | Watchos | < 26.0 |
| Webkitgtk | Webkitgtk | < 2.50.1 |
| Wpewebkit | Wpe Webkit | < 2.50.1 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/125108Release NotesVendor Advisory
- https://support.apple.com/en-us/125110
- https://support.apple.com/en-us/125113Release NotesVendor Advisory
- https://support.apple.com/en-us/125114Release NotesVendor Advisory
- https://support.apple.com/en-us/125115Release NotesVendor Advisory
- https://support.apple.com/en-us/125116Release NotesVendor Advisory
- http://seclists.org/fulldisclosure/2025/Sep/49Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/53Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/57Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/59Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2025/10/13/4Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:19946
- https://security-tracker.debian.org/tracker/CVE-2025-43343
- https://ubuntu.com/security/CVE-2025-43343
- https://webkitgtk.org/security/WSA-2025-0007.html
FAQ
What is CVE-2025-43343?
CVE-2025-43343 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web cont...
How severe is CVE-2025-43343?
CVE-2025-43343 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-43343?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari, Apple Ipados, Apple Iphone Os, Apple Macos, Apple Tvos.