CVE-2025-43541
massType Confusion in Apple Safari Leads to Browser Crash (iOS, macOS, visionOS)
CVE-2025-43541 is a type confusion issue (CWE-843) in Safari's handling of web content, addressed by Apple with improved state handling, affecting the browser across iOS, iPadOS, macOS and visionOS. It is triggered when an unpatched browser processes maliciously crafted web content, for example when a user visits an attacker-crafted webpage. The impact is availability-only: the CVSS 3.1 vector (4.3 medium, C:N/I:N/A:L) shows no confidentiality or integrity impact, and the gain for an attacker is an unexpected Safari crash (denial of service). All users of unpatched Safari on the listed Apple platforms are affected, and fixes shipped in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2 and visionOS 26.2. There is no public PoC, no CISA KEV listing and no confirmed in-the-wild exploitation, but EPSS assigns a 33.5% probability of exploitation in the next 30 days (98th percentile), an unusually high score for a crash-only bug.
What to do: Upgrade to Safari 26.2, iOS/iPadOS 18.7.3 or iOS/iPadOS 26.2, macOS Tahoe 26.2 and visionOS 26.2, and verify endpoints (including via MDM fleet reporting) are running these builds. No workaround exists beyond limiting exposure to untrusted web content until patched. Given the availability-only impact and no known exploitation, patching on the normal cadence is defensible, but the high EPSS (33.5%) argues against long deferral.
| apple safari | versions prior to 26.2 |
| apple iphone os | versions prior to iOS 18.7.3 (legacy branch) and prior to iOS 26.2 (current branch) |
| apple ipados | versions prior to iPadOS 18.7.3 (legacy branch) and prior to iPadOS 26.2 (current branch) |
| apple macos | macOS Tahoe versions prior to 26.2 |
| apple visionos | versions prior to 26.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
- Vendors
- apple
- Products
- safari, ipados, iphone os, macos, visionos
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.