VulnerabilityModified
CVE-2025-43342
Processing maliciously crafted web content may lead to an unexpected process crash.
CRITICAL 9.8EPSS 0.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos · webkitgtk/webkitgtk · wpewebkit/wpe webkit
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/125108Release Notes, Vendor Advisory
- https://support.apple.com/en-us/125109Release Notes, Vendor Advisory
- https://support.apple.com/en-us/125110
- https://support.apple.com/en-us/125113Release Notes, Vendor Advisory
- https://support.apple.com/en-us/125114Release Notes, Vendor Advisory
- https://support.apple.com/en-us/125115Release Notes, Vendor Advisory
- https://support.apple.com/en-us/125116Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Sep/49Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/53Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/57Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Sep/59Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/09/22/3Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.