
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43511 is a use-after-free vulnerability in Apple's WebKit Web Inspector component that can cause an unexpected process crash when processing maliciously crafted web content. It was discovered by 이동하 (Lee Dong Ha of BoB 14th) and disclosed by Apple on December 12, 2025. The vulnerability affects iOS and iPadOS before 18.7.2, and has been subsequently fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by CISA-ADP (Apple iOS 18.7.2, Apple iOS 26.2, Apple Safari 26.2).
The vulnerability is classified as CWE-416 (Use After Free), residing specifically in the WebKit Web Inspector component (WebKit Bugzilla: 300926). A use-after-free condition occurs when the browser engine accesses memory that has already been freed during the processing of maliciously crafted web content, leading to an unexpected process crash. Exploitation requires user interaction — a victim must visit or process attacker-controlled web content — but no special privileges are required. Apple addressed the issue with improved memory management (Apple iOS 18.7.2, Apple Safari 26.2).
Successful exploitation of this vulnerability results in an unexpected process crash, primarily impacting availability (denial of service) of the affected browser or web content rendering process. There is no assessed confidentiality or integrity impact based on the CVSS scoring. The scope is limited to the affected process and does not indicate privilege escalation or lateral movement potential based on currently available information (Apple iOS 18.7.2, Apple iOS 26.2).
Apple has released patches addressing this vulnerability across multiple platforms. Users should update to the following versions or later: iOS 18.7.2 and iPadOS 18.7.2 (released November 5, 2025), iOS 26.2 and iPadOS 26.2, Safari 26.2, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2 (all released December 12, 2025). No configuration-based workarounds have been published; updating to a patched version is the recommended remediation. Vulnerability scanners including Qualys and Nessus have detection plugins available for this CVE (Apple iOS 18.7.2, Apple iOS 26.2, Apple Safari 26.2).
The vulnerability received standard coverage as part of Apple's December 2025 security update cycle, with technology media outlets such as 9to5Mac and Lifehacker covering the broader iOS 26.2 and iOS 18.7.2 security releases. The CIS issued an advisory noting multiple vulnerabilities in Apple products that could allow for arbitrary code execution in the same update batch. No notable individual researcher commentary specific to CVE-2025-43511 has been identified beyond the discoverer credit to Lee Dong Ha of BoB 14th (Apple iOS 18.7.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."