PT-2025-51892 · Apple+7 · Ipados+12

Hossein Lotfi

+1

·

Published

2025-12-12

·

Updated

2026-01-20

·

CVE-2025-43501

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apple Safari versions prior to 26.2 iOS versions prior to 18.7.3 iPadOS versions prior to 18.7.3 macOS Tahoe versions prior to 26.2 visionOS versions prior to 26.2 WebKitGTK (affected versions not specified) webkit2gtk in Debian Linux (affected versions not specified) webkit2gtk3 in SberLinux (affected versions not specified) wpewebkit in Debian Linux (affected versions not specified)
Description This issue is a buffer overflow in Apple Safari’s JavaScriptCore and WebKitGTK, stemming from improper memory handling when processing maliciously crafted web content. This can lead to an unexpected process crash. The issue was addressed by improving memory handling. There is no mention of the number of potentially affected devices or any real-world incidents where this issue was exploited.
Recommendations Update Apple Safari to version 26.2 or later. Update iOS to version 18.7.3 or later. Update iPadOS to version 18.7.3 or later. Update macOS Tahoe to version 26.2 or later. Update visionOS to version 26.2 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for WebKitGTK, webkit2gtk in Debian Linux, webkit2gtk3 in SberLinux, and wpewebkit in Debian Linux.

Fix

RCE

DoS

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:23663
ALSA-2025:23700
BDU:2026-03310
CVE-2025-43501
DLA-4414-1
DSA-6083-1
MGASA-2025-0331
OPENSUSE-SU-2026:20065-1
RHSA-2025:23975
SUSE-SU-2025:4527-1
SUSE-SU-2025:4528-1
SUSE-SU-2026:0021-1
SUSE-SU-2026:20102-1
USN-7957-1
ZDI-25-1126

Affected Products

Almalinux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Ubuntu
Ios
Ipados
Macos Tahoe
Visionos