
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43501 is a buffer overflow vulnerability in Apple's WebKit engine (JavaScriptCore HashTable expansion) that can cause an unexpected process crash when processing maliciously crafted web content. It was discovered by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative and disclosed on December 12, 2025, when Apple released patches across multiple platforms. Affected software includes Safari (before 26.2), iOS and iPadOS (before 18.7.3 and before 26.2), macOS Tahoe (before 26.2), and visionOS (before 26.2). The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by CISA-ADP (Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3, ZDI Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write) and CWE-120 (Buffer Copy without Checking Size of Input), stemming from improper validation of user-supplied data during HashTable expansion in JavaScriptCore, WebKit's JavaScript engine. Specifically, an integer overflow can occur before a memory write during HashTable resize operations, leading to an out-of-bounds write condition. The attack vector is network-based and requires user interaction — a victim must visit a malicious web page or open a malicious file in a WebKit-based browser. The ZDI advisory (ZDI-25-1126) provides additional technical context, noting the flaw exists within HashTable expansion handling and that an attacker can leverage it to execute code in the context of the current process (ZDI Advisory, Apple Advisory iOS 18.7.3).
Successful exploitation can lead to an unexpected process crash (denial of service) in the WebKit rendering process, and according to the ZDI advisory, may also enable arbitrary code execution in the context of the browser process. The primary impact is availability (process crash), with potential for code execution if the overflow is reliably controlled. Because WebKit is sandboxed on Apple platforms, direct system compromise would typically require chaining with additional privilege escalation vulnerabilities; however, the crash itself can disrupt browsing sessions and potentially expose users to further exploitation (ZDI Advisory, Apple Advisory visionOS 26.2).
.crash files) in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/ referencing com.apple.WebKit.WebContent or JavaScriptCore; repeated WebKit process crashes logged in system logs.com.apple.WebKit.WebContent; WebKit renderer process crashing and restarting repeatedly during a browsing session..crash or .ips diagnostic files with stack traces referencing JavaScriptCore HashTable or memory allocation functions.Apple has released patches addressing CVE-2025-43501 across all affected platforms: Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, and visionOS 26.2, all released December 12, 2025. Users should update their devices immediately via Settings > General > Software Update (iOS/iPadOS) or System Settings > General > Software Update (macOS). No configuration-based workarounds are available; upgrading to a patched version is the only remediation (Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3, Apple Advisory macOS Tahoe 26.2).
The vulnerability was reported by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative, who also published ZDI-25-1126 on December 17, 2025, providing technical details about the HashTable expansion integer overflow. The December 2025 Apple patch batch received broad media coverage due to the inclusion of two actively exploited WebKit zero-days (CVE-2025-43529 and CVE-2025-14174) in the same release, with outlets such as CyberSecurityNews and 9to5Mac urging immediate updates. The SANS Internet Storm Center also noted the release. CVE-2025-43501 itself was not the primary focus of coverage but was highlighted in technical summaries of the patch batch (ZDI Advisory, Apple Advisory iOS 26.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."