CVE-2025-43457: Use After Free
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Other sources
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
— Red Hat
Accessibility. A permissions issue was addressed with additional restrictions.
— Apple
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Admin Framework. The issue was addressed with improved checks.
— Apple
App Store. A logging issue was addressed with improved data redaction.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.1 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 26.1 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.1 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 26.1 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 26.1 - Configuration
Apply the update that fixes the file quarantine bypass by adding additional checks in the quarantine handling component.
quarantine file quarantine bypass = addressed with additional checks - Configuration
Apply the update that addresses the permissions issue by adding additional sandbox restrictions.
Sandbox sandbox restrictions = additional sandbox restrictions - Configuration
Apply the update that addresses the issue by restricting options offered on a locked device.
Safari (locked device option restrictions) options offered on a locked device = restricted - Configuration
Apply the Safari/WebKit update that fixes the parsing/input validation issues by improving validation and bounds checking.
WebKit input/path validation = improved checks/bounds validation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43379
- CVE-2025-43448
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43507
- CVE-2025-43400
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43459
- CVE-2025-43503
- CVE-2025-43500
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43443
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43392
- CVE-2025-43407
- CVE-2025-43423
- CVE-2025-43498
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43389
- CVE-2025-43439
- CVE-2025-43493
- CVE-2025-43502
- CVE-2025-43427
- CVE-2025-43441
- CVE-2025-43421
- CVE-2025-43442
- CVE-2025-43449
- CVE-2025-43450
- CVE-2025-43426
- CVE-2025-43350
- CVE-2025-43437
- CVE-2025-43424
- CVE-2025-43391
- CVE-2025-46316
- CVE-2025-43454
- CVE-2025-43418
- CVE-2025-43460
- CVE-2025-43422
- CVE-2025-43452
- CVE-2025-43495
- CVE-2025-43471
- CVE-2025-43322
- CVE-2025-46313
- CVE-2025-43390
- CVE-2025-43388
- CVE-2025-43466
- CVE-2025-43382
- CVE-2025-43468
- CVE-2025-43378
- CVE-2025-43478
- CVE-2025-43446
- CVE-2025-43465
- CVE-2025-43497
- CVE-2025-43394
- CVE-2025-43395
- CVE-2025-43461
- CVE-2025-43401
- CVE-2025-43479
- CVE-2025-43381
- CVE-2025-43481
- CVE-2025-43470
- CVE-2025-46315
- CVE-2025-43387
- CVE-2025-43420
- CVE-2025-43464
- CVE-2025-43348
- CVE-2025-43474
- CVE-2025-43396
- CVE-2025-43467
- CVE-2025-43377
- CVE-2025-43364
- CVE-2025-43506
- CVE-2025-43469
- CVE-2025-43411
- CVE-2025-43508
- CVE-2025-43405
- CVE-2025-43393
- CVE-2024-43398
- CVE-2024-49761
- CVE-2025-6442
- CVE-2025-43406
- CVE-2025-43404
- CVE-2025-43339
- CVE-2025-43335
- CVE-2025-43408
- CVE-2025-43476
- CVE-2025-30465
- CVE-2025-43414
- CVE-2025-43473
- CVE-2025-43499
- CVE-2025-43380
- CVE-2025-43477
- CVE-2025-43399
- CVE-2025-43336
- CVE-2025-43397
- CVE-2025-43409
- CVE-2025-43351
- CVE-2025-43463
- CVE-2025-32462
- CVE-2025-43334
- CVE-2025-43412
- CVE-2025-53906
- CVE-2025-43373
- CVE-2025-43402
- CVE-2025-43472
Frequently Asked Questions
What is the severity of CVE-2025-43457?
CVE-2025-43457 is classified as a critical vulnerability due to the potential for exploitation leading to an unexpected crash in Safari.
How do I fix CVE-2025-43457?
To fix CVE-2025-43457, update to watchOS 26.1, iOS 26.1, iPadOS 26.1, Safari 26.1, or visionOS 26.1.
What types of devices are affected by CVE-2025-43457?
CVE-2025-43457 affects devices running watchOS, iOS, iPadOS, Safari, and visionOS prior to version 26.1.
What does the use-after-free vulnerability in CVE-2025-43457 entail?
The use-after-free vulnerability in CVE-2025-43457 may allow attackers to manipulate memory, resulting in crashes or potential code execution.
Is there a workaround for CVE-2025-43457?
There are no known workarounds for CVE-2025-43457; updating the software to version 26.1 is the recommended solution.