{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-43529",
  "revision": 1,
  "title": "Apple WebKit — use-after-free in web content to code execution",
  "summary": "Safari 26.2, iOS and iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2 and the matching tvOS, visionOS and watchOS builds use memory after releasing it on crafted web content. Apple reports use in an extremely sophisticated targeted attack.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.08763,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2025-12-15",
    "prerequisites": "The user must open attacker-controlled web content in an affected browser or embedded view."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Safari 26.2",
      "iOS 18.7.3",
      "iPadOS 18.7.3",
      "iOS 26.2",
      "iPadOS 26.2",
      "macOS Tahoe 26.2",
      "tvOS 26.2",
      "visionOS 26.2",
      "watchOS 26.2"
    ]
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update to Safari 26.2, iOS and iPadOS 18.7.3 or 26.2, macOS Tahoe 26.2 and the matching 26.2 builds now; look closely at likely targets' devices.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-43529",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43529",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/125884"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/125885"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/125886"
    }
  ],
  "published_at": "2025-12-17T21:16:11.570Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "apple",
    "webkit",
    "safari",
    "use-after-free",
    "targeted-attack",
    "kev"
  ]
}
