VYPR
Medium severity4.3NVD Advisory· Published Nov 4, 2025· Updated Apr 2, 2026

CVE-2025-43441

CVE-2025-43441

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A memory handling issue in WebKit allows processing malicious web content to cause an unexpected process crash, fixed in Apple's latest OS updates.

CVE-2025-43441 is a memory handling vulnerability in WebKit that can be triggered by processing maliciously crafted web content, leading to an unexpected process crash. The issue was addressed with improved memory handling.

An attacker could craft a malicious webpage that, when visited by a user on an affected Apple device, causes a crash of the browser or application rendering the content. No user interaction beyond visiting the page is required, but the attack requires the user to load the malicious content.

The primary impact is denial of service due to process crash. There is no indication of code execution or data compromise. The CVSS score of 4.3 reflects the low severity.

Apple has released patches in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, and visionOS 26.1 [1][2][3][4]. Users should update their devices to the latest versions.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.