CVE-2025-43272

The issue was addressed with improved memory handling. This issue is fixed in visionOS 26, Safari 26, iOS 26 and iPadOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

04 Nov 2025, 22:16

Type Values Removed Values Added
Summary (en) The issue was addressed with improved memory handling. This issue is fixed in Safari 26, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash. (en) The issue was addressed with improved memory handling. This issue is fixed in visionOS 26, Safari 26, iOS 26 and iPadOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References
  • {'url': 'https://support.apple.com/en-us/125110', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • () http://seclists.org/fulldisclosure/2025/Sep/53 -
  • () http://seclists.org/fulldisclosure/2025/Sep/57 -
  • () http://seclists.org/fulldisclosure/2025/Sep/59 -
  • () http://www.openwall.com/lists/oss-security/2025/09/22/3 -

Information

Published : 2025-09-15 23:15

Updated : 2025-11-04 22:16


NVD link : CVE-2025-43272

Mitre link : CVE-2025-43272

CVE.ORG link : CVE-2025-43272


JSON object : View

Products Affected

apple

  • watchos
  • visionos
  • ipados
  • iphone_os
  • safari
  • macos
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer