Apple Multiple Products Use-After-Free WebKit Vulnerability

Release Date: 15th of December 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2025-43529 is a use-after-free vulnerability in WebKit, the browser engine used by Safari and all WebKit-based browsers on Apple platforms. A use-after-free occurs when software continues to reference memory that has already been freed, which can lead to memory corruption and remote code execution (RCE) when processing crafted content. This vulnerability is actively exploited in the wild.

 

References

  1. https://threatprotect.qualys.com/2025/12/16/apple-warns-of-zero-day-vulnerability-exploited-in-attack-cve-2025-43529/
  2. https://support.apple.com/en-us/125886
  3. https://support.apple.com/en-us/125885