CVE-2025-43529
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2025-43529 is a use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing maliciously crafted web content. Discovered and reported by Google's Threat Analysis Group, it was disclosed and patched on December 12, 2025. The vulnerability affects iOS before 18.7.3, iOS/iPadOS 26.0–26.2, macOS Tahoe before 26.2, tvOS before 26.2, watchOS before 26.2, visionOS before 26.2, and Safari before 26.2. Apple confirmed active exploitation in "extremely sophisticated" targeted attacks against specific individuals on iOS versions before iOS 26. It carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory, Apple Advisory iOS 18.7.3).

Technical details

The root cause is a use-after-free (CWE-416) in WebKit's memory management, tracked as WebKit Bugzilla #302502. The flaw arises when WebKit processes maliciously crafted web content, allowing a freed memory region to be accessed and potentially controlled by an attacker. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious web page — but requires no authentication or special privileges, making it accessible via drive-by browser attacks. The vulnerability was reported by Google's Threat Analysis Group and was paired with a companion vulnerability CVE-2025-14174 (a memory corruption issue in WebKit) in the same attack chain. It was later incorporated into the "DarkSword" iOS exploit kit, a multi-stage exploit chain using six vulnerabilities (including three zero-days) for full device takeover (Apple Advisory, Google Cloud Blog).

Impact

Successful exploitation enables arbitrary code execution in the context of the WebKit rendering process, which can lead to complete device compromise. Attackers can access sensitive data (including credentials, crypto wallets, and personal files), install malware or spyware (such as GHOSTBLADE), and perform unauthorized actions on the device. Apple confirmed the vulnerability was exploited in "extremely sophisticated, targeted attacks against specific individuals," indicating high-value targeting consistent with mercenary spyware or nation-state operations. The DarkSword exploit kit incorporating this flaw was observed stealing personal data and cryptocurrency wallet contents from iPhone users across multiple countries (Apple Advisory, Google Cloud Blog, Feedly).

Exploitation steps

  1. Reconnaissance: Identify high-value targets (journalists, activists, executives, government officials) running iOS versions before 18.7.3 or iOS 26.0–26.1 using OSINT or targeted intelligence gathering.
  2. Deliver malicious link: Send the target a crafted URL via phishing message, email, or social engineering, directing them to an attacker-controlled or compromised legitimate website hosting the exploit.
  3. Trigger WebKit use-after-free: When the victim's Safari or WebKit-based browser loads the malicious page, specially crafted JavaScript or web content triggers the use-after-free condition in WebKit (CVE-2025-43529), corrupting freed memory.
  4. Chain with companion vulnerability: The DarkSword exploit kit chains CVE-2025-43529 with CVE-2025-14174 (memory corruption) and up to four additional vulnerabilities to achieve a full sandbox escape and kernel-level code execution.
  5. Deploy payload: Once code execution is achieved, the attacker deploys an infostealer payload (e.g., GHOSTBLADE) that exfiltrates personal data, credentials, and cryptocurrency wallet contents from the device.
  6. Persist and exfiltrate: The malware establishes persistence and silently transmits stolen data to attacker-controlled infrastructure (Google Cloud Blog, BleepingComputer, The Hacker News).

Indicators of compromise

  • Network: Outbound connections from the device to unknown or suspicious IP addresses/domains following web browsing activity; unusual data exfiltration patterns (large or repeated outbound transfers).
  • Network: Connections to command-and-control infrastructure associated with GHOSTBLADE or DarkSword campaigns; DNS queries to newly registered or suspicious domains after visiting unfamiliar links.
  • Logs: Unexpected WebKit process crashes or restarts in device diagnostic logs; crash reports referencing memory access violations in WebKit or Safari processes.
  • File System: Presence of unexpected processes or binaries installed outside normal app directories; new configuration profiles installed without user consent.
  • Process: Unusual child processes spawned by Safari or WebKit (e.g., shell commands, network utilities); background processes with elevated privileges not associated with installed apps.
  • Device Behavior: Unexpected battery drain, increased data usage, or device slowdown following web browsing; Apple threat notifications warning of mercenary spyware targeting (Google Cloud Blog, Lookout).

Mitigation and workarounds

Apple released patches on December 12, 2025. Users should update to: iOS 18.7.3 or iOS 26.2 (and corresponding iPadOS versions), macOS Tahoe 26.2, tvOS 26.2, watchOS 26.2, visionOS 26.2, or Safari 26.2. Apple subsequently expanded iOS 18 updates to additional older iPhone models to block DarkSword attacks. No configuration-based workaround is available; patching is the only effective mitigation. Organizations should enforce mandatory updates across all Apple devices immediately, prioritizing high-value individuals at elevated risk of targeted attacks. Users should avoid clicking suspicious links or loading untrusted web content until patched (Apple Advisory, Apple Advisory iOS 18.7.3, CISA KEV, BleepingComputer).

Community reactions

Apple confirmed the vulnerability was exploited in "extremely sophisticated" targeted attacks, a rare and significant public acknowledgment. Google's Threat Analysis Group (TAG), which discovered and reported the flaw, subsequently published a detailed report on the DarkSword exploit kit that weaponized CVE-2025-43529, attributing its use to multiple state-sponsored threat actors and commercial spyware vendors. Security researchers and media widely covered the disclosure, with Forbes, BleepingComputer, The Hacker News, and PCMag urging immediate updates. CISA added the CVE to its KEV catalog and later ordered federal agencies to patch DarkSword-related iOS flaws. The security community noted the sophistication of the exploit chain and the breadth of affected Apple platforms. Lookout and SentinelOne also published threat intelligence on the DarkSword campaign (Google Cloud Blog, BleepingComputer, SentinelOne).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-43735HIGH8.1
  • Apple Safari logoApple Safari
  • WebKit
NoYesJun 29, 2026
CVE-2026-43746MEDIUM6.5
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesJun 29, 2026
CVE-2026-43745MEDIUM6.5
  • Apple Safari logoApple Safari
  • pywebkitgtk
NoYesJun 29, 2026
CVE-2026-43742MEDIUM6.5
  • Apple Safari logoApple Safari
  • wpewebkit
NoYesJun 29, 2026
CVE-2026-43740MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkit2gtk3-jsc-devel
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management