
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43541 is a type confusion vulnerability in Apple's WebKit engine (JavaScriptCore FTL JIT compiler) affecting the handling of the DataView byteLength property. By performing specific JavaScript actions, a remote attacker can trigger a type confusion condition that may lead to an unexpected Safari crash or arbitrary code execution in the context of the browser process. The vulnerability was discovered by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative and disclosed on December 12, 2025, when Apple released patches. Affected products include Safari (before 26.2), iOS and iPadOS (before 18.7.3 and before 26.2), macOS Tahoe (before 26.2), and visionOS (before 26.2). The CVSS v3.1 base score is 4.3 (Medium), as assessed by CISA-ADP (Apple Advisory Safari, Apple Advisory iOS 26.2, Apple Advisory iOS 18.7.3).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / Type Confusion) and resides in WebKit's JavaScriptCore FTL (Faster Than Light) JIT compiler, specifically in the handling of the DataView byteLength property. By crafting malicious JavaScript that manipulates DataView objects in a specific sequence, an attacker can cause the engine to access memory using an incompatible type, leading to a type confusion condition. Exploitation requires the target user to visit a malicious webpage or open a malicious file containing the crafted JavaScript — no authentication or elevated privileges are required on the attacker's side. A ZDI advisory (ZDI-25-1127) and a public proof-of-concept on GitHub provide additional technical detail on the exploitation mechanics (ZDI Advisory, PoC GitHub, Apple Advisory iOS 26.2).
Successful exploitation can result in an unexpected Safari crash (denial of service) or, in more severe scenarios, arbitrary code execution within the context of the Safari/WebKit process. The ZDI advisory and Feedly intelligence indicate that an attacker can leverage this vulnerability to execute code with the privileges of the current browser process, potentially enabling data theft, further exploitation of the device, or use as a stepping stone in a chained attack. The vulnerability affects a broad range of Apple devices running Safari, iOS, iPadOS, macOS, and visionOS, significantly widening the attack surface (ZDI Advisory, Apple Advisory iOS 18.7.3).
DataView objects and their byteLength property in a sequence that triggers the type confusion condition in WebKit's JavaScriptCore FTL JIT compiler.DataView byteLength handling flaw causes a type confusion condition in the JIT-compiled code path./Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/ referencing com.apple.WebKit.WebContent or JavaScriptCore with type confusion or memory access errors; system logs showing repeated WebKit process terminations.Apple has released patches addressing CVE-2025-43541 in the following updates, all released December 12, 2025: Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, and visionOS 26.2. Users should immediately update their Apple devices to these versions or later via System Settings > General > Software Update (iOS/iPadOS/macOS) or the App Store (Safari on macOS). Until patches are applied, users should avoid visiting untrusted websites or opening files from unknown sources in Safari, and consider using web content filtering or alternative browsers where feasible (Apple Advisory Safari, Apple Advisory iOS 18.7.3, Apple Advisory macOS Tahoe 26.2).
The vulnerability was discovered and reported by Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative, who also published the ZDI advisory ZDI-25-1127 on December 17, 2025. The December 2025 Apple patch batch received broad media coverage, with outlets such as CyberSecurityNews and 9to5Mac highlighting the WebKit fixes and the associated actively exploited zero-days (CVE-2025-43529 and CVE-2025-14174) in the same release. The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products that could allow arbitrary code execution. Linux distributions including Debian, Red Hat, Fedora, Ubuntu, and SUSE also issued WebKitGTK security updates addressing this CVE, reflecting its cross-platform relevance (ZDI Advisory, Apple Advisory iOS 26.2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."