DNA View

CVE-2025-43536

Medium
Low Medium High Critical
4.3
CVSS Score
Published: Dec 17, 2025
Last Modified: Dec 18, 2025

Vulnerability Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Tahoe 26.2, iOS 26.2 and iPadOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
U
Confidentiality
N
Integrity
N
Availability
L

Available Security Patches

5 patches available from vendors

View All Patches
Canonical (Ubuntu)

USN-7957-1

USN-7957-1: WebKitGTK vulnerabilities

Severity
Unknown
Released
Jan 13, 2026
Security Update
SUSE

CVE-2025-43536

CVE-2025-43536

Severity
Unknown
Released
Dec 23, 2025
Security Update
Debian

DSA-6083-1

DSA-6083-1 webkit2gtk - security update

Severity
Unknown
Released
Dec 18, 2025
Security Update
Red Hat

RHSA-2025:23663

RHSA-2025:23663: webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

Severity
Unknown
Released
Dec 17, 2025
Security Update
Red Hat

RHSA-2025:23700

RHSA-2025:23700: webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

Severity
Unknown
Released
Dec 17, 2025
Security Update

Severity Details

4.3
out of 10.0
Medium

Key Information

Published Date
December 17, 2025