Web Content Processing Vulnerability in Apple Safari and iOS Products
CVE-2025-43440

6.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-43440?

A vulnerability has been identified in Apple’s Safari and various iOS platforms that could allow maliciously crafted web content to cause an unexpected crash of processes. Improved checks have been introduced to address this issue across all affected versions, which include Safari 26.1, iOS 26.1, iPadOS 26.1, tvOS 26.1, visionOS 26.1, and watchOS 26.1. Users are encouraged to update to the latest versions to mitigate potential risks.

Affected Version(s)

iOS and iPadOS < 26.1

Safari < 26.1

tvOS < 26.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.