CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 5.6% of known CVEs.
Dec 15, 2025
Jan 05, 2026
Threat Analysis
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://support.apple.com/en-us/125884
https://support.apple.com/en-us/125884
https://support.apple.com/en-us/125892
https://support.apple.com/en-us/125892
https://support.apple.com/en-us/125885
https://support.apple.com/en-us/125885
https://support.apple.com/en-us/125886
https://support.apple.com/en-us/125886
https://support.apple.com/en-us/125889
https://support.apple.com/en-us/125889
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2025-43529