
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43529 is a use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing maliciously crafted web content. Discovered and reported by Google's Threat Analysis Group, it was disclosed and patched on December 12, 2025. The vulnerability affects iOS before 18.7.3, iOS/iPadOS 26.0–26.2, macOS Tahoe before 26.2, tvOS before 26.2, watchOS before 26.2, visionOS before 26.2, and Safari before 26.2. Apple confirmed active exploitation in "extremely sophisticated" targeted attacks against specific individuals on iOS versions before iOS 26. It carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory, Apple Advisory iOS 18.7.3).
The root cause is a use-after-free (CWE-416) in WebKit's memory management, tracked as WebKit Bugzilla #302502. The flaw arises when WebKit processes maliciously crafted web content, allowing a freed memory region to be accessed and potentially controlled by an attacker. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious web page — but requires no authentication or special privileges, making it accessible via drive-by browser attacks. The vulnerability was reported by Google's Threat Analysis Group and was paired with a companion vulnerability CVE-2025-14174 (a memory corruption issue in WebKit) in the same attack chain. It was later incorporated into the "DarkSword" iOS exploit kit, a multi-stage exploit chain using six vulnerabilities (including three zero-days) for full device takeover (Apple Advisory, Google Cloud Blog).
Successful exploitation enables arbitrary code execution in the context of the WebKit rendering process, which can lead to complete device compromise. Attackers can access sensitive data (including credentials, crypto wallets, and personal files), install malware or spyware (such as GHOSTBLADE), and perform unauthorized actions on the device. Apple confirmed the vulnerability was exploited in "extremely sophisticated, targeted attacks against specific individuals," indicating high-value targeting consistent with mercenary spyware or nation-state operations. The DarkSword exploit kit incorporating this flaw was observed stealing personal data and cryptocurrency wallet contents from iPhone users across multiple countries (Apple Advisory, Google Cloud Blog, Feedly).
Apple released patches on December 12, 2025. Users should update to: iOS 18.7.3 or iOS 26.2 (and corresponding iPadOS versions), macOS Tahoe 26.2, tvOS 26.2, watchOS 26.2, visionOS 26.2, or Safari 26.2. Apple subsequently expanded iOS 18 updates to additional older iPhone models to block DarkSword attacks. No configuration-based workaround is available; patching is the only effective mitigation. Organizations should enforce mandatory updates across all Apple devices immediately, prioritizing high-value individuals at elevated risk of targeted attacks. Users should avoid clicking suspicious links or loading untrusted web content until patched (Apple Advisory, Apple Advisory iOS 18.7.3, CISA KEV, BleepingComputer).
Apple confirmed the vulnerability was exploited in "extremely sophisticated" targeted attacks, a rare and significant public acknowledgment. Google's Threat Analysis Group (TAG), which discovered and reported the flaw, subsequently published a detailed report on the DarkSword exploit kit that weaponized CVE-2025-43529, attributing its use to multiple state-sponsored threat actors and commercial spyware vendors. Security researchers and media widely covered the disclosure, with Forbes, BleepingComputer, The Hacker News, and PCMag urging immediate updates. CISA added the CVE to its KEV catalog and later ordered federal agencies to patch DarkSword-related iOS flaws. The security community noted the sophistication of the exploit chain and the breadth of affected Apple platforms. Lookout and SentinelOne also published threat intelligence on the DarkSword campaign (Google Cloud Blog, BleepingComputer, SentinelOne).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."