CVE-2025-43209
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
- Affected products
- Apple Macos, Safari, Ios, Ipados, Macos Sequoia, Macos Sonoma, Macos Ventura, Tvos
- Apple Ipados
- < 17.7.9, 18.6
- Apple Iphone Os
- < 18.6
- Apple Macos
- < 13.7.7, 14.7.7, 15.6
- Apple Tvos
- < 18.6
- Apple Visionos
- < 2.6
- Apple Watchos
- < 11.6
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2025-07-29
CVE-2025-43209 at NVD
8 known exploits for CVE-2025-43209
Proof-of-concept code and exploit modules indexed by Sploitus
π Apple Security Advisory 07-29-2025-5
π Apple Security Advisory 07-29-2025-4
π Apple Security Advisory 07-29-2025-6
π Apple Security Advisory 07-29-2025-7
π Apple Security Advisory 07-29-2025-8
π Apple Security Advisory 07-29-2025-1
π Apple Security Advisory 07-29-2025-2
π Apple Security Advisory 07-29-2025-3