CVE-2025-43431
EUVD-2025-3768904.11.2025, 02:15
The issue was addressed with improved memory handling. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, visionOS 26.1. Processing maliciously crafted web content may lead to memory corruption.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apple | safari | 𝑥 < 26.1 |
| apple | ipados | 𝑥 < 26.1 |
| apple | iphone_os | 𝑥 < 26.1 |
| apple | tvos | 𝑥 < 26.1 |
| apple | visionos | 𝑥 < 26.1 |
| apple | watchos | 𝑥 < 26.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkitgtk |
| ||||||||||||||
| webkit2gtk |
| ||||||||||||||
| qtwebkit-source |
| ||||||||||||||
| qtwebkit-opensource-src |
| ||||||||||||||
| wpewebkit |
|
Common Weakness Enumeration
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.