
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43531 is a race condition vulnerability in Apple's WebKit browser engine that can cause an unexpected process crash when processing maliciously crafted web content. It is classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization) and was discovered by Phil Pizlo of Epic Games. The vulnerability was publicly disclosed on December 12, 2025, and affects iOS/iPadOS before 18.7.3, iOS/iPadOS 26.x before 26.2, macOS Tahoe before 26.2, Safari before 26.2, tvOS before 26.2, visionOS before 26.2, and watchOS before 26.2. It carries a CVSS v3.1 base score of 3.1 (Low) as assessed by CISA-ADP (Apple iOS 18.7.3, Apple iOS 26.2, Apple tvOS 26.2).
The root cause is a race condition (CWE-362) in WebKit's state handling, tracked internally as WebKit Bugzilla #301940. The flaw arises from improper synchronization when concurrent execution paths access shared resources during web content processing, which can lead to an unexpected process crash. Exploitation requires user interaction — specifically, a victim must visit or be directed to a maliciously crafted web page — and the attack is delivered over the network with high attack complexity. Apple addressed the issue with improved state handling in the patched releases (Apple iOS 18.7.3, Apple macOS Tahoe 26.2).
Successful exploitation of CVE-2025-43531 can cause an unexpected process crash in the WebKit rendering process, resulting in a denial-of-service condition for the affected application (e.g., Safari or any WebKit-based browser). The CVSS assessment reflects a limited availability impact with no direct confidentiality or integrity impact for this specific CVE. However, it is part of a broader cluster of WebKit vulnerabilities (including CVE-2025-43529 and CVE-2025-14174) that were reportedly used together in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 26, where the combined chain could lead to arbitrary code execution (Apple iOS 18.7.3, Apple iOS 26.2).
Apple has released patches addressing CVE-2025-43531 across all affected platforms. Users should update to the following versions or later: iOS 18.7.3 and iPadOS 18.7.3 (for legacy devices), iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, Safari 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2 — all released December 12, 2025. No configuration-based workaround is available; updating to a patched version is the only remediation. Given the association with sophisticated targeted attacks on iOS, immediate patching is strongly recommended, particularly for high-risk individuals (Apple iOS 18.7.3, Apple iOS 26.2, Apple macOS Tahoe 26.2).
Apple's security advisories explicitly noted that related WebKit vulnerabilities in the same patch batch (CVE-2025-43529 and CVE-2025-14174) were exploited in "extremely sophisticated" targeted attacks against specific individuals on iOS before iOS 26, drawing significant attention from the security community. Coverage appeared across technology media including 9to5Mac, Lifehacker, and CyberPress, as well as security-focused outlets such as SANS ISC and CyberSecAsia, highlighting the urgency of the December 2025 update cycle. The CIS also issued an advisory noting multiple vulnerabilities in Apple products could allow for arbitrary code execution (Apple iOS 18.7.3, Moonlock).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."