CVE-2025-43529High· 8.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malici…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 1.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the CISA ADP record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Jan 5, 2026
Disclosed via CVEORG
Last analysed / modified upstream
8.8%
7 GitHub repos (last check)
Added to the CISA catalog on Dec 15, 2025. Federal remediation due Jan 5, 2026. View catalog ↗
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Safari < 26.2ios_and_ipados < 18.7.3ios_and_ipados < 26.2macOS < 26.2tvOS < 26.2visionOS < 26.2watchOS < 26.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-43000High· 8.8A use-after-free issue was addressed with improved memory management
CVE-2025-31277High· 8.8The issue was addressed with improved memory handling
CVE-2026-65351Medium· 4.3This issue was addressed through improved state management
CVE-2026-43715High· 8.8A use-after-free issue was addressed with improved memory management
CVE-2026-65332Medium· 4.3This issue was addressed through improved state management
CVE-2026-64718Medium· 5.5A use-after-free issue was addressed with improved memory management