CVE-2025-43541
MEDIUMDescription
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apple | safari |
| apple | ipados |
| apple | ipados |
| apple | iphone_os |
| apple | iphone_os |
| apple | macos |
| apple | visionos |
References
Frequently Asked Questions
What is CVE-2025-43541? +
How severe is CVE-2025-43541? +
What products are affected by CVE-2025-43541? +
How do I check if I'm vulnerable to CVE-2025-43541? +
Related Vulnerabilities
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. …
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We …
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation …
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device …
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as …
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion …