CVE-2025-43440
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2025-43440 is a WebKit vulnerability in Apple's browser engine that allows processing maliciously crafted web content to lead to an unexpected process crash. The flaw was addressed with improved checks and is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, and watchOS 26.1. It was discovered by Nan Wang (@eternalsakura13) and disclosed on November 3, 2025, when Apple released the patched versions (Apple iOS Advisory, Apple tvOS Advisory). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by CISA-ADP (Apple visionOS Advisory).

Technical details

The vulnerability resides in WebKit (tracked as WebKit Bugzilla: 298126) and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting) by CISA-ADP, though Apple's advisory describes the root fix as "improved checks" applied to web content processing logic. The Feedly intelligence data also notes a use-after-free component in related WebKit issues from the same release, and Apple's description for CVE-2025-43440 specifically states the issue was addressed with improved checks in the WebKit engine. Exploitation requires user interaction — specifically, a victim must visit or process a maliciously crafted web page — and no authentication or special privileges are required from the attacker (Apple iOS Advisory, Apple tvOS Advisory).

Impact

Successful exploitation causes an unexpected process crash in the WebKit rendering engine, resulting in a denial-of-service condition for the affected browser or web content consumer. The primary impact is availability (rated High in CVSS), with no assessed confidentiality or integrity impact. Affected platforms span a wide range of Apple devices including iPhone, iPad, Apple TV, Apple Watch, Apple Vision Pro, and Safari on macOS, making the potential user population very large (Apple iOS Advisory, Apple visionOS Advisory, Apple watchOS Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Apple iOS Advisory).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, and watchOS 26.1. No configuration-based workaround is available; updating to the patched release is the only recommended remediation. IBM has also issued an advisory for IBM Observability with Instana (OnPrem) products that incorporate the affected WebKit component (Apple iOS Advisory, Apple tvOS Advisory, IBM Advisory).

Community reactions

The vulnerability was part of a broader November 3, 2025 Apple security release that addressed numerous WebKit and OS-level issues across the Apple ecosystem. Coverage appeared on technology news outlets including 9to5Mac and Times of India, which highlighted the importance of updating Apple devices promptly. The SANS Internet Storm Center also noted the release in a diary entry. The vulnerability received standard scanner coverage from Qualys and Tenable/Nessus shortly after disclosure, indicating routine industry tracking without exceptional alarm (9to5Mac, SANS ISC).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783HIGH8.8
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757HIGH8.8
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719HIGH8.1
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesJul 27, 2026
CVE-2026-64730MEDIUM6.5
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728MEDIUM6.5
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management