Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
900 articles · 101759 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2025-43529KEVEXPLOITEDPATCHED
apple · safari

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, vision

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

Affected Products

VendorProductVersions
applesafari< 26.2, < 18.7.3, < 26.2, < 18.7.3, < 26.2, < 26.2, < 26.2, < 26.2, < 26.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
appleipadoscve_cpe95%
applemacoscve_cpe95%
appletvoscve_cpe95%
applevisionoscve_cpe95%
applewatchoscve_cpe95%

References

  • https://support.apple.com/en-us/125884(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125885(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125886(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125889(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125890(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125891(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/125892(Release Notes, Vendor Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43529(US Government Resource)

Related News (2 articles)

Tier D
BleepingComputer5h ago
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
→ No new info (linked only)
Tier E
Lobsters Security7d ago
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
26.218.7.3
CWECWE-416
PublishedDec 17, 2025
Last enriched7h ago
Trending Score106🔥
Source articles2
Independent2
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20700EXPKEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memo
Trending: 106
MEDIUMCVE-2026-28861
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious web
Trending: 15
MEDIUMCVE-2026-20665
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watc
Trending: 15
MEDIUMCVE-2026-20691
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted
Trending: 15
MEDIUMCVE-2026-20664
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lea
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Dec 17, 2025
Added to CISA KEV
Dec 17, 2025
Actively Exploited
Dec 18, 2025
Exploit Available
Dec 18, 2025
Patch Available
Dec 18, 2025
Discovered by ZDM
Apr 1, 2026