« List of all CVEs

CVE-2025-43342

Published: 9/15/2025 Last updated: 11/4/2025 Reserved: 4/16/2025

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26, iOS 18.7 and iPadOS 18.7. Processing maliciously crafted web content may lead to an unexpected process crash.

CNA assigner: apple (286789f9-fbc2-4510-9f9a-43facdede74c) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (1)

javascriptcore

Products affected (12)

Product Vendor Version
watchOS Apple n/a
iOS and iPadOS Apple < 55e55eb65fd5e09faf5a0e49ffcdd37905aaf4da
iOS and iPadOS Apple n/a
Safari Apple n/a
tvOS Apple Version 1809 for 32-bit Systems
visionOS Apple < 5a95815b17428ce2f56ec18da5e0d1b2a1a15240
iOS and iPadOS Apple Snapdragon 835 Mobile PC Platform
iOS and iPadOS Apple Snapdragon 845 Mobile Platform
Safari Apple < 6.1.7601.27017
tvOS Apple Snapdragon 855 Mobile Platform
visionOS Apple Snapdragon 855+/860 Mobile Platform (SM8150-AC)
watchOS Apple < 6.1.7601.27017

References (22)