CVE-2025-43441
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory handling issue in WebKit allows processing malicious web content to cause an unexpected process crash, fixed in Apple's latest OS updates.
CVE-2025-43441 is a memory handling vulnerability in WebKit that can be triggered by processing maliciously crafted web content, leading to an unexpected process crash. The issue was addressed with improved memory handling.
An attacker could craft a malicious webpage that, when visited by a user on an affected Apple device, causes a crash of the browser or application rendering the content. No user interaction beyond visiting the page is required, but the attack requires the user to load the malicious content.
The primary impact is denial of service due to process crash. There is no indication of code execution or data compromise. The CVSS score of 4.3 reflects the low severity.
Apple has released patches in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, and visionOS 26.1 [1][2][3][4]. Users should update their devices to the latest versions.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <26.1
- (no CPE)range: <26.1
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <26.1
- (no CPE)range: <18.7.2
- Range: <18.7.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.