CVE-2025-43541
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2025-43541 is a type confusion vulnerability in Apple's WebKit engine (JavaScriptCore FTL JIT compiler) affecting the handling of the DataView byteLength property. By performing specific JavaScript actions, a remote attacker can trigger a type confusion condition that may lead to an unexpected Safari crash or arbitrary code execution in the context of the browser process. The vulnerability was discovered by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative and disclosed on December 12, 2025, when Apple released patches. Affected products include Safari (before 26.2), iOS and iPadOS (before 18.7.3 and before 26.2), macOS Tahoe (before 26.2), and visionOS (before 26.2). The CVSS v3.1 base score is 4.3 (Medium), as assessed by CISA-ADP (Apple Advisory Safari, Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3).

Technical details

The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / Type Confusion) and resides in WebKit's JavaScriptCore FTL (Faster Than Light) JIT compiler, specifically in the handling of the DataView byteLength property. By crafting malicious JavaScript that manipulates DataView objects in a specific sequence, an attacker can cause the engine to access memory using an incompatible type, leading to a type confusion condition. Exploitation requires the target user to visit a malicious webpage or open a malicious file containing the crafted JavaScript — no authentication or elevated privileges are required on the attacker's side. A ZDI advisory (ZDI-25-1127) and a public proof-of-concept on GitHub provide additional technical detail on the exploitation mechanics (ZDI Advisory, PoC GitHub, Apple Advisory iOS 26.2).

Impact

Successful exploitation can result in an unexpected Safari crash (denial of service) or, in more severe scenarios, arbitrary code execution within the context of the Safari/WebKit process. The ZDI advisory and Feedly intelligence indicate that an attacker can leverage this vulnerability to execute code with the privileges of the current browser process, potentially enabling data theft, further exploitation of the device, or use as a stepping stone in a chained attack. The vulnerability affects a broad range of Apple devices running Safari, iOS, iPadOS, macOS, and visionOS, significantly widening the attack surface (ZDI Advisory, Apple Advisory iOS 18.7.3).

Exploitation steps

  1. Reconnaissance: Identify targets using vulnerable Apple devices (Safari on macOS, iOS/iPadOS before 18.7.3 or 26.2, visionOS before 26.2) via social engineering, phishing, or watering-hole attack setup.
  2. Craft malicious JavaScript payload: Develop a JavaScript payload that manipulates DataView objects and their byteLength property in a sequence that triggers the type confusion condition in WebKit's JavaScriptCore FTL JIT compiler.
  3. Host malicious page or file: Deploy the crafted JavaScript on a web server under attacker control, or embed it in a malicious file (e.g., HTML attachment) to be delivered to the target.
  4. Deliver to target: Lure the victim into visiting the malicious URL (via phishing, malvertising, or watering-hole) or opening the malicious file in Safari.
  5. Trigger type confusion: When the victim's browser processes the malicious web content, the DataView byteLength handling flaw causes a type confusion condition in the JIT-compiled code path.
  6. Achieve code execution or crash: Depending on exploit reliability and memory layout, the attacker achieves arbitrary code execution within the Safari/WebKit process context, or at minimum causes a denial-of-service crash (ZDI Advisory, PoC GitHub).

Indicators of compromise

  • Network: Outbound connections from Safari or WebKit-based processes to unexpected or newly registered domains; unusual HTTP/HTTPS requests to attacker-controlled infrastructure following web browsing activity.
  • Process: Unexpected child processes spawned by Safari or WebKit content processes (e.g., shell commands, network utilities); Safari crashes or repeated WebContent process restarts logged in system crash reports.
  • Logs: Crash reports in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/ referencing com.apple.WebKit.WebContent or JavaScriptCore with type confusion or memory access errors; system logs showing repeated WebKit process terminations.
  • File System: Unexpected files written to user-accessible directories by the Safari process; new launch agents or persistence mechanisms created shortly after browser activity on untrusted sites.

Mitigation and workarounds

Apple has released patches addressing CVE-2025-43541 in the following updates, all released December 12, 2025: Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, and visionOS 26.2. Users should immediately update their Apple devices to these versions or later via System Settings > General > Software Update (iOS/iPadOS/macOS) or the App Store (Safari on macOS). Until patches are applied, users should avoid visiting untrusted websites or opening files from unknown sources in Safari, and consider using web content filtering or alternative browsers where feasible (Apple Advisory Safari, Apple Advisory iOS 18.7.3, Apple Advisory macOS Tahoe 26.2).

Community reactions

The vulnerability was discovered and reported by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative, who also published the ZDI advisory ZDI-25-1127 on December 17, 2025. The December 2025 Apple patch batch received broad media coverage, with outlets such as CyberSecurityNews and 9to5Mac highlighting the WebKit fixes and the associated actively exploited zero-days (CVE-2025-43529 and CVE-2025-14174) in the same release. The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products that could allow arbitrary code execution. Linux distributions including Debian, Red Hat, Fedora, Ubuntu, and SUSE also issued WebKitGTK security updates addressing this CVE, reflecting its cross-platform relevance (ZDI Advisory, Apple Advisory iOS 26.2).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management