Vulnerability intelligence
CVE-2025-43529
Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple Multiple Products
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
CVSS Score
—
Unrated
EPSS — Exploit Probability
8.9%
Riskier than 95% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2025-12-15
Remediation
Unconfirmed
Federal deadline 2026-01-05
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-01-05.
9 articles across 6 outlets · first covered Feb 12, 2026 · latest Mar 19, 2026
Coverage timeline
-
DarkSword emerges as powerful iOS exploit tool in global attackssecurityaffairs.com · Mar 19, 2026
-
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeoverthehackernews.com · Mar 19, 2026
-
DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alikewww.darkreading.com · Mar 18, 2026
-
‘DarkSword’ iOS Exploit Kit Used by State-Sponsored Hackers, Spyware Vendorswww.securityweek.com · Mar 18, 2026
-
Apple patches zero-day flaw that could let attackers take control of deviceswww.malwarebytes.com · Feb 12, 2026
-
Apple fixed first actively exploited zero-day in 2026securityaffairs.com · Feb 12, 2026
-
Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’www.securityweek.com · Feb 12, 2026
-
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devicesthehackernews.com · Feb 12, 2026
-
Apple Zero-Day (CVE-2026-20700) Exploited in the Wildsecurityonline.info · Feb 12, 2026