CVE-2025-43511
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2025-43511 is a use-after-free vulnerability in Apple's WebKit Web Inspector component that can cause an unexpected process crash when processing maliciously crafted web content. It was discovered by 이동하 (Lee Dong Ha of BoB 14th) and disclosed by Apple on December 12, 2025. The vulnerability affects iOS and iPadOS before 18.7.2, and has been subsequently fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by CISA-ADP (Apple iOS 18.7.2, Apple iOS 26.2, Apple Safari 26.2).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), residing specifically in the WebKit Web Inspector component (WebKit Bugzilla: 300926). A use-after-free condition occurs when the browser engine accesses memory that has already been freed during the processing of maliciously crafted web content, leading to an unexpected process crash. Exploitation requires user interaction — a victim must visit or process attacker-controlled web content — but no special privileges are required. Apple addressed the issue with improved memory management (Apple iOS 18.7.2, Apple Safari 26.2).

Impact

Successful exploitation of this vulnerability results in an unexpected process crash, primarily impacting availability (denial of service) of the affected browser or web content rendering process. There is no assessed confidentiality or integrity impact based on the CVSS scoring. The scope is limited to the affected process and does not indicate privilege escalation or lateral movement potential based on currently available information (Apple iOS 18.7.2, Apple iOS 26.2).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across multiple platforms. Users should update to the following versions or later: iOS 18.7.2 and iPadOS 18.7.2 (released November 5, 2025), iOS 26.2 and iPadOS 26.2, Safari 26.2, macOS Tahoe 26.2, visionOS 26.2, and watchOS 26.2 (all released December 12, 2025). No configuration-based workarounds have been published; updating to a patched version is the recommended remediation. Vulnerability scanners including Qualys and Nessus have detection plugins available for this CVE (Apple iOS 18.7.2, Apple iOS 26.2, Apple Safari 26.2).

Community reactions

The vulnerability received standard coverage as part of Apple's December 2025 security update cycle, with technology media outlets such as 9to5Mac and Lifehacker covering the broader iOS 26.2 and iOS 18.7.2 security releases. The CIS issued an advisory noting multiple vulnerabilities in Apple products that could allow for arbitrary code execution in the same update batch. No notable individual researcher commentary specific to CVE-2025-43511 has been identified beyond the discoverer credit to Lee Dong Ha of BoB 14th (Apple iOS 18.7.2).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management