PT-2025-51037 · Apple +5 · Apple Macos +12

Published

2025-12-12

·

Updated

2026-01-14

·

CVE-2025-43529

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple products (affected versions not specified) Fedora 43 webkitgtk versions prior to 2.50.4 webkit2gtk in Debian
Description This is a use-after-free issue within the WebKit component, found in Apple products, Fedora, and Debian. The vulnerability allows for potential arbitrary code execution when processing maliciously crafted web content. This flaw has been actively exploited in the wild, with reports indicating sophisticated attacks targeting specific individuals. The vulnerability stems from improper memory management within WebKit’s HTML parsing logic. Exploitation may lead to memory corruption, potentially enabling attackers to execute code, trigger crashes, or bypass security restrictions. The vulnerability is present in multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, as well as the Safari browser. It is also present in webkitgtk and webkit2gtk.
Recommendations Update all Apple devices and the Safari browser to the latest available versions. Update webkitgtk to version 2.50.4 or later. Update webkit2gtk in Debian to the latest available version.

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-00005
CVE-2025-43529
DLA-4414-1
DSA-6083-1

Affected Products

Almalinux
Centos
Debian
Apple Macos
Red Hat
Rocky Linux
Safari
Webkit
Ios
Ipados
Tvos
Visionos
Watchos