CVE-2025-43342

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26, iOS 18.7 and iPadOS 18.7. Processing maliciously crafted web content may lead to an unexpected process crash.
References
Link Resource
https://support.apple.com/en-us/125108 Release Notes Vendor Advisory
https://support.apple.com/en-us/125109 Release Notes Vendor Advisory
https://support.apple.com/en-us/125113 Release Notes Vendor Advisory
https://support.apple.com/en-us/125114 Release Notes Vendor Advisory
https://support.apple.com/en-us/125115 Release Notes Vendor Advisory
https://support.apple.com/en-us/125116 Release Notes Vendor Advisory
http://seclists.org/fulldisclosure/2025/Sep/49 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2025/Sep/53 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2025/Sep/57 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2025/Sep/59 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/09/22/3 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

History

20 Nov 2025, 17:40

Type Values Removed Values Added
First Time Webkitgtk webkitgtk
Webkitgtk
Wpewebkit
Wpewebkit wpe Webkit
CPE cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*
cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
References () http://seclists.org/fulldisclosure/2025/Sep/49 - () http://seclists.org/fulldisclosure/2025/Sep/49 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/53 - () http://seclists.org/fulldisclosure/2025/Sep/53 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/57 - () http://seclists.org/fulldisclosure/2025/Sep/57 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/59 - () http://seclists.org/fulldisclosure/2025/Sep/59 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/09/22/3 - () http://www.openwall.com/lists/oss-security/2025/09/22/3 - Mailing List, Third Party Advisory

04 Nov 2025, 22:16

Type Values Removed Values Added
Summary (en) A correctness issue was addressed with improved checks. This issue is fixed in tvOS 26, Safari 26, iOS 18.7 and iPadOS 18.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. (en) A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26, iOS 18.7 and iPadOS 18.7. Processing maliciously crafted web content may lead to an unexpected process crash.
References
  • {'url': 'https://support.apple.com/en-us/125110', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}
  • () http://seclists.org/fulldisclosure/2025/Sep/49 -
  • () http://seclists.org/fulldisclosure/2025/Sep/53 -
  • () http://seclists.org/fulldisclosure/2025/Sep/57 -
  • () http://seclists.org/fulldisclosure/2025/Sep/59 -
  • () http://www.openwall.com/lists/oss-security/2025/09/22/3 -

Information

Published : 2025-09-15 23:15

Updated : 2025-11-20 17:40


NVD link : CVE-2025-43342

Mitre link : CVE-2025-43342

CVE.ORG link : CVE-2025-43342


JSON object : View

Products Affected

wpewebkit

  • wpe_webkit

apple

  • watchos
  • visionos
  • ipados
  • iphone_os
  • safari
  • tvos
  • macos

webkitgtk

  • webkitgtk
CWE
CWE-20

Improper Input Validation