Improper Input Validation in Safari and iOS Products by Apple
CVE-2025-43443

4.3MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
4 November 2025

What is CVE-2025-43443?

A vulnerability has been identified in Apple’s Safari and related iOS products that allows maliciously crafted web content to trigger unexpected process crashes. This issue arises from inadequate input validation, which can lead to stability issues within the affected applications. Apple has addressed the flaw with enhanced checks to ensure more robust handling of web content across its platforms, including Safari, visionOS, watchOS, iOS, iPadOS, and tvOS.

Affected Version(s)

iOS and iPadOS < 26.1

Safari < 26.1

tvOS < 26.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.