CVE-2025-43501
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2025-43501 is a buffer overflow vulnerability in Apple's WebKit engine (JavaScriptCore HashTable expansion) that can cause an unexpected process crash when processing maliciously crafted web content. It was discovered by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative and disclosed on December 12, 2025, when Apple released patches across multiple platforms. Affected software includes Safari (before 26.2), iOS and iPadOS (before 18.7.3 and before 26.2), macOS Tahoe (before 26.2), and visionOS (before 26.2). The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by CISA-ADP (Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3, ZDI Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write) and CWE-120 (Buffer Copy without Checking Size of Input), stemming from improper validation of user-supplied data during HashTable expansion in JavaScriptCore, WebKit's JavaScript engine. Specifically, an integer overflow can occur before a memory write during HashTable resize operations, leading to an out-of-bounds write condition. The attack vector is network-based and requires user interaction — a victim must visit a malicious web page or open a malicious file in a WebKit-based browser. The ZDI advisory (ZDI-25-1126) provides additional technical context, noting the flaw exists within HashTable expansion handling and that an attacker can leverage it to execute code in the context of the current process (ZDI Advisory, Apple Advisory iOS 18.7.3).

Impact

Successful exploitation can lead to an unexpected process crash (denial of service) in the WebKit rendering process, and according to the ZDI advisory, may also enable arbitrary code execution in the context of the browser process. The primary impact is availability (process crash), with potential for code execution if the overflow is reliably controlled. Because WebKit is sandboxed on Apple platforms, direct system compromise would typically require chaining with additional privilege escalation vulnerabilities; however, the crash itself can disrupt browsing sessions and potentially expose users to further exploitation (ZDI Advisory, Apple Advisory visionOS 26.2).

Exploitation steps

  1. Reconnaissance: Identify targets running unpatched versions of Safari, iOS/iPadOS (before 18.7.3 or 26.2), macOS Tahoe (before 26.2), or visionOS (before 26.2) using passive fingerprinting or social engineering.
  2. Craft malicious web content: Develop a specially crafted HTML/JavaScript page that triggers JavaScriptCore's HashTable expansion logic with inputs designed to cause an integer overflow before a memory write operation.
  3. Deliver payload: Host the malicious page on an attacker-controlled server and lure the target into visiting it (e.g., via phishing link, malicious advertisement, or compromised website).
  4. Trigger the overflow: When the victim's browser processes the crafted JavaScript, the HashTable expansion integer overflow occurs, resulting in an out-of-bounds write to memory.
  5. Achieve objective: Depending on exploit reliability and memory layout, the outcome ranges from a process crash (denial of service) to potential arbitrary code execution within the WebKit renderer process sandbox (ZDI Advisory, Apple Advisory iOS 18.7.3).

Indicators of compromise

  • Network: Unexpected outbound connections from Safari or WebKit-based app processes to unknown external hosts following web browsing activity; unusual HTTP/HTTPS requests to newly registered or low-reputation domains.
  • Logs: Crash reports (.crash files) in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/ referencing com.apple.WebKit.WebContent or JavaScriptCore; repeated WebKit process crashes logged in system logs.
  • Process: Unexpected child processes spawned by com.apple.WebKit.WebContent; WebKit renderer process crashing and restarting repeatedly during a browsing session.
  • File System: Presence of suspicious .crash or .ips diagnostic files with stack traces referencing JavaScriptCore HashTable or memory allocation functions.

Mitigation and workarounds

Apple has released patches addressing CVE-2025-43501 across all affected platforms: Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, and visionOS 26.2, all released December 12, 2025. Users should update their devices immediately via Settings > General > Software Update (iOS/iPadOS) or System Settings > General > Software Update (macOS). No configuration-based workarounds are available; upgrading to a patched version is the only remediation (Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3, Apple Advisory macOS Tahoe 26.2).

Community reactions

The vulnerability was reported by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative, who also published ZDI-25-1126 on December 17, 2025, providing technical details about the HashTable expansion integer overflow. The December 2025 Apple patch batch received broad media coverage due to the inclusion of two actively exploited WebKit zero-days (CVE-2025-43529 and CVE-2025-14174) in the same release, with outlets such as CyberSecurityNews and 9to5Mac urging immediate updates. The SANS Internet Storm Center also noted the release. CVE-2025-43501 itself was not the primary focus of coverage but was highlighted in technical summaries of the patch batch (ZDI Advisory, Apple Advisory iOS 26.2).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management