Medium CVSS 8.8 webkit Logic Error CISA KEV

Overview

Medium
Severity
8.8
CVSS
No
Exploited ITW
Embargoed
Fix Status
DescriptionProcessing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report.
ComponentWebKit
Bug ClassLogic Error
Tracker303614
CWECWE-787, CWE-119 (Out-of-bounds write, Buffer bounds error)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEVListed
CreditedApple and Google Threat Analysis Group
Disclosed2025-12-12

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.

Original Bug Report

The reporter's bug is still restricted on the tracker.