CVE-2025-43343

T

he issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

History

17 Dec 2025, 15:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:19946 -
  • () https://security-tracker.debian.org/tracker/CVE-2025-43343 -
  • () https://ubuntu.com/security/CVE-2025-43343 -
  • () https://webkitgtk.org/security/WSA-2025-0007.html -

20 Nov 2025, 17:40

Type Values Removed Values Added
First Time Wpewebkit wpe Webkit
Webkitgtk
Wpewebkit
Webkitgtk webkitgtk
References () http://seclists.org/fulldisclosure/2025/Sep/49 - () http://seclists.org/fulldisclosure/2025/Sep/49 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/53 - () http://seclists.org/fulldisclosure/2025/Sep/53 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/57 - () http://seclists.org/fulldisclosure/2025/Sep/57 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2025/Sep/59 - () http://seclists.org/fulldisclosure/2025/Sep/59 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/10/13/4 - () http://www.openwall.com/lists/oss-security/2025/10/13/4 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/10/13/4 -

04 Nov 2025, 02:15

Type Values Removed Values Added
Summary (en) The issue was addressed with improved memory handling. This issue is fixed in tvOS 26, Safari 26, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected process crash. (en) The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
References
  • {'url': 'https://support.apple.com/en-us/125110', 'tags': ['Release Notes', 'Vendor Advisory'], 'source': '[email protected]'}

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Sep/49 -
  • () http://seclists.org/fulldisclosure/2025/Sep/53 -
  • () http://seclists.org/fulldisclosure/2025/Sep/57 -
  • () http://seclists.org/fulldisclosure/2025/Sep/59 -

17 Sep 2025, 14:05

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 23:15

Updated : 2025-12-17 15:15


NVD link : CVE-2025-43343

Mitre link : CVE-2025-43343

CVE.ORG link : CVE-2025-43343


JSON object : View

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer