A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/125632 | Vendor Advisory Release Notes |
| https://support.apple.com/en-us/125638 | Vendor Advisory Release Notes |
| https://support.apple.com/en-us/125639 | Vendor Advisory Release Notes |
| https://support.apple.com/en-us/125640 | Vendor Advisory Release Notes |
Configurations
Configuration 1 (hide)
|
History
04 Nov 2025, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.apple.com/en-us/125632 - Vendor Advisory, Release Notes | |
| References | () https://support.apple.com/en-us/125638 - Vendor Advisory, Release Notes | |
| References | () https://support.apple.com/en-us/125639 - Vendor Advisory, Release Notes | |
| References | () https://support.apple.com/en-us/125640 - Vendor Advisory, Release Notes | |
| First Time |
Apple watchos
Apple Apple ipados Apple safari Apple visionos Apple iphone Os |
|
| CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
04 Nov 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CWE | CWE-416 |
04 Nov 2025, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-04 02:15
Updated : 2025-11-04 19:05
NVD link : CVE-2025-43438
Mitre link : CVE-2025-43438
CVE.ORG link : CVE-2025-43438
JSON object : View
Products Affected
apple
- watchos
- safari
- visionos
- iphone_os
- ipados
CWE
CWE-416
Use After Free
