CVE-2025-43529Active Exploitation(apple / ipados)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 51 mentions across 38 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 32 signals
  • General: 12 classified signals
  • Disclosure: 10 classified signals
  • Peaked 33d ago at 4 mentions (2026-02-01); latest day: 1
  • 51 total mentions across 38 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafaritvosvisionoswatchos

Deep dive

Activity timeline51 mentions / 38d
01234Mentions · 2026-01-27: 1Mentions · 2026-01-28: 3Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-02-01: 4Mentions · 2026-02-02: 1Mentions · 2026-02-07: 1Mentions · 2026-02-11: 1Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-02: 3Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Mentions · 2026-03-21: 2Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-04-01: 1Mentions · 2026-04-11: 1Mentions · 2026-04-23: 1Mentions · 2026-05-01: 1Mentions · 2026-06-11: 1Mentions · 2026-09-01: 2Mentions · 2026-09-15: 1Mentions · 2026-09-19: 1Mentions · 2026-09-21: 1Mentions · 2026-10-04: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-03-02: 2PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-06-11: 1Exploit Tool / Code · 2026-02-01: 1Exploit Tool / Code · 2026-03-02: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-04-01: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-01: 2Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-09-01: 2Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-09-01: 1Patch / Workaround · 2026-09-21: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 2Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-11: 1Technical Details · 2026-05-01: 1Technical Details · 2026-06-11: 1Technical Details · 2026-09-01: 2Technical Details · 2026-09-15: 1Technical Details · 2026-09-19: 101-2701-3002-0702-1302-2703-0403-1503-1803-2304-0105-0109-1510-0410-08
Signal classification6 categories
Active Exploitation
1326.5%
General
1224.5%
Disclosure
1020.4%
Patch
714.3%
PoC
612.2%
Exploit
12.0%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-283
Active Exploitation1General1PoC1
2026-01-291
General1
2026-01-301
Disclosure1
2026-02-014
Active Exploitation2Exploit1General1
2026-02-021
General1
2026-02-071
General1
2026-02-111
Patch1
2026-02-123
Active Exploitation2Patch1
2026-02-131
Active Exploitation1
2026-02-151
Disclosure1
2026-02-231
Patch1
2026-02-271
General1
2026-02-281
Disclosure1
2026-03-023
General1PoC2
2026-03-041
General1
2026-03-051
General1
2026-03-061
PoC1
2026-03-152
General1PoC1
2026-03-161
Patch1
2026-03-171
General1
2026-03-181
Patch1
2026-03-212
Disclosure1Patch1
2026-03-221
Disclosure1
2026-03-232
Active Exploitation1Disclosure1
2026-03-251
Active Exploitation1
2026-03-271
Active Exploitation1
2026-04-011
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-231
Disclosure1
2026-05-011
General1
2026-06-111
PoC1
2026-09-012
Active Exploitation2
2026-09-151
Disclosure1
2026-09-191
Disclosure1
2026-09-211
Patch1
Full discourse20 posts
  • Jack Ren@bjrjk
    Exploit

    A carefully structured, tiered root cause analysis for CVE-2025-43529 (JSC UAF). Spent quite some time refining the structure to make the reasoning explicit and readable. Shoutout to @jir4vv1t for his detailed analysis and exploit. https://github.com/bjrjk/CVE-2025-43529

    Post summary

    The post points to a GitHub repo that offers a root‑cause analysis and an exploit for CVE‑2025‑43529, a JSC use‑after‑free vulnerability.

    23101336810.6K
    663 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    How Browser Exploits Work: A Case Study of CVE-2025-43529 (DarkSword iOS Chain) https://8ksec.io/how-browser-exploits-work-darksword-ios-cve-2025-43529/ https://t.co/yBjljPQfGq

    Post summary

    The text announces a case study about CVE-2025-43529 (DarkSword iOS Chain), indicating a new disclosure but lacking explicit PoC, exploit code, or active exploitation evidence.

    1181108677.7K
    967 followersView on X
  • dbugs@ptdbugs
    Disclosure

    iOS Exploit for Sale (CVE-2025-43529, CVE-2026-20700, CVE-2025-14174) Read on dbugs: https://dbu.gs/news/ios-exploit-for-sale-cve-2025-43529-cve-2026-20700-cve-2025-14174-20260914 Vulnerable versions: Apple iOS 15.0–18.2 Price: $10k (3 hands max), $18k (1 hand only) According to the author’s description, the exploit relies on well-known CVEs and a web trigger via the Safari browser. This implies a scenario in which the vulnerability can be triggered after opening a specially crafted webpage in Safari. CVE-2025-43529 (https://dbu.gs/vulnerability/PT-2025-51037?fts%5Bvalue%5D=CVE-2025-43529) - a use-after-free vulnerability in WebKit, where a specially crafted web page could lead to the execution of arbitrary code. CVE-2025-14174 (https://dbu.gs/vulnerability/PT-2025-50966?fts%5Bvalue%5D=CVE-2025-14174) - another WebKit vulnerability related to a memory corruption when processing malicious web content. CVE-2026-20700 (https://dbu.gs/vulnerability/PT-2026-7805?fts%5Bvalue%5D=CVE-2026-20700) — a memory corruption vulnerability in the dyld component that, when combined with an existing write-to-memory capability, could allow arbitrary code execution. iOS remains the second-largest mobile OS in the world: according to StatCounter, as of May 2026, its share of the mobile operating system market was 31,95% (https://web.telegram.org/a/%20%20%20%20https://gs.statcounter.com/os-market-share/mobile/worldwide) globally. CVE-2025-14174 — PT-2025-50966: https://dbu.gs/vulnerability/PT-2025-50966 CVE-2025-43529 — PT-2025-51037: https://dbu.gs/vulnerability/PT-2025-51037 CVE-2026-20700 — PT-2026-7805: https://dbu.gs/vulnerability/PT-2026-7805

    Post summary

    The text discloses an iOS exploit for sale leveraging CVE-2025-43529, CVE-2025-14174, and CVE-2026-20700, providing technical details of their vulnerabilities but no patch, tool, or active exploitation evidence.

    7154825543.5K
    3.6K followersView on X
  • marcchoc93@marcchoc934
    PoC

    https://docs.google.com/spreadsheets/d/1T0MLyqE-NO4CURAwytUUiNLDNaYo2Ig_CsGnM2pImYo/edit?usp=drivesdk 🔥 PS5 - CVE-2025-43529: UAF confirmed, ROP gadgets found ✅ Reproducible UAF (10 objects, pattern 1/2) ✅ Base libkernel: 0x0823ef8000 ✅ ROP gadgets: pop rdi/rsi/rdx/rax, syscall ✅ Socketpair thread sync functional ✅ Tests T-001 to T-011 passed (crashes) ❌ MISSING: - addrof/fakeobj (critical) - mov [rdi], rax / mov rax, [rdi] - RIP control stable (10-20%) - thr_new broken 👉 ROP researchers, the ball is in your court! Of course, testing is necessary. I'm cutting myself off here; I can't go any further. It's up to the developers to test and give me a report. Don't criticize; I'm doing this to perhaps move things forward, or not. Thank you for your kindness. Tested with 2yjb version 1.3, Gezine version PS5 11.00 slime. Not tested before or after this version. Thank you. jir4vv1t its github https://github.com/jir4vv1t/CVE-2025-43529

    Post summary

    The text confirms a use‑after‑free vulnerability in PS5, details ROP gadgets, and provides a GitHub link with proof‑of‑concept code, but does not mention active exploitation, patches, or false positives.

    6120102117.6K
    201 followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    CVE-2026-20700(Dynamic linker): An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

    Post summary

    CVE‑2026‑20700 is reported to have been actively exploited against targeted iOS users, with attackers able to execute arbitrary code via a memory‑write vulnerability in the dynamic linker; no patch or mitigation is mentioned.

    090653310.5K
    39.9K followersView on X
  • ZEE JAILBREAK@ZeeJailbreak
    PoC

    Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://github.com/zeroxjf/WebKit-UAF-ANGLE-OOB-Analysis/tree/main https://t.co/ZcGzBe18Tk

    Post summary

    The tweet directs readers to a GitHub repository containing analysis and likely PoC code for the WebKit UAF and ANGLE OOB vulnerabilities, detailing an exploit chain for iOS Safari on iOS 26.1.

    013061276.5K
    8.1K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari - iOS 26.1 https://github.com/zeroxjf/WebKit-UAF-ANGLE-OOB-Analysis/tree/main

    Post summary

    The post announces an analysis and GitHub repository that provides a Proof of Concept for an exploit chain involving WebKit UAF and ANGLE OOB vulnerabilities on iOS Safari 26.1, but does not report active exploitation or a patch.

    08040364.9K
    2.0K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    Exploit chain analysis! CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 https://github.com/SgtBattenHA/Analysis

    Post summary

    The tweet references a GitHub analysis of an exploit chain for CVE-2025-43529 and CVE-2025-14174, indicating that proof‑of‑concept code or analysis is available, without evidence of active exploitation or patches.

    18041172.5K
    2.7K followersView on X
  • GenericCoding@GenericCoding
    PoC

    Will add writeup and future avenues of research shortly. Putting on GitHub to invite contributions from the community. Currently we have neither read nor write but can reference a memory address arbitrarily. Patched in 26.2, only tested on 26.1. https://github.com/GenericCoding/cve-2025-43529-arbitrary-ref/tree/main

    Post summary

    A GitHub repository for CVE‑2025‑43529 has been released as a PoC, providing code that demonstrates referencing any memory address. The vulnerability is marked as patched in version 26.2.

    1412948.2K
    715 followersView on X
  • hackyboiz@hackyboiz2
    Disclosure

    [1day1line] CVE-2025-43529: Use-after-free in JavaScriptCore caused by missing escape propagation to Phi nodes in the DFG StoreBarrierInsertionPhase Hello, this is gongjae. Today's 1day1line covers a use-after-free vulnerability in WebKit's JavaScriptCore. The DFG JIT recognized that a Phi node had escaped, but it did not apply escape handling to the values flowing into that Phi through Upsilon nodes, so the required StoreBarrier was never inserted. As a result, the concurrent GC misses an object it should have scanned, and a live object ends up being freed. Please refer to the blog post for details! https://hackyboiz.github.io/2026/09/19/gongjae/CVE-2025-43529/

    Post summary

    The tweet discloses CVE‑2025‑43529, a use‑after‑free in JavaScriptCore caused by missing escape propagation to Phi nodes in the DFG StoreBarrierInsertionPhase, resulting in a concurrent GC bug that can free a live object; no PoC, exploit, or patch information is provided.

    0302161.5K
    577 followersView on X
  • Kameleonre_@Kameleonre_
    PoC

    Original repo: https://github.com/jir4vv1t/CVE-2025-43529

    Post summary

    The tweet provides a link to a GitHub repository named after CVE‑2025‑43529, suggesting a proof‑of‑concept exists, but offers no additional context or details.

    0301712.8K
    26.7K followersView on X
  • Anas@Naz_style
    General

    @khanhduytran0 CVE that might be useful for IOS 18 JB Kernel CVE-2024-54518 CVE-2024-54522 CVE-2024-54523 Sandbox/ Privilege CVE-2024-54468 CVE-2024-54529 CVE-2024-54535 WebKit CVE-2024-54543 CVE-2025-14174 CVE-2025-43529 CVE-2025-43300

    Post summary

    The tweet enumerates a set of CVEs that may be useful for an iOS 18 jailbreak but offers no additional details, links, or evidence of exploitation.

    010134902
    75 followersView on X
  • 𝕄𝕒𝕩@Mexrl
    Patch

    @PROGG_1 WebKit is still possible tho. 12.50 and 52 could work with WebKit because exploit bugs were found in WebKit that could work with ps4. CVE-2025-43529 (Use-After-Free in WebKit): Patched in December 2025, CVE-2025-24201 (Sandbox Escape), CVE-2025-14174. I read a lot so yeah.

    Post summary

    The tweet highlights WebKit vulnerabilities (CVE‑2025‑43529, CVE‑2025‑24201, CVE‑2025‑14174), notes that CVE‑2025‑43529 was patched in December 2025, and provides technical details but no PoC, exploit code, or evidence of active exploitation.

    10070346
    533 followersView on X
  • ApplSec@ApplSec
    Patch

    🐛 CVE-2025-14174 (dyld) additional patches, 🐛 CVE-2025-43529 (dyld) additional patches, 🐛 CVE-2026-20700 (dyld): - iOS and iPadOS 26.3 - macOS Tahoe 26.3 - tvOS 26.3 - visionOS 26.3 - watchOS 26.3

    Post summary

    The message announces that additional patches for three dyld CVEs have been released, specifying that they apply to iOS, iPadOS, macOS, tvOS, visionOS, and watchOS 26.3.

    11031477
    1.3K followersView on X
  • Rahmi@rhmi_fii
    General

    iOS: CVE-nya lebih sedikit (317 CVE), TAPI zero-day-nya elit & targeted. Contoh CVE-2026-20700 sama CVE-2025-43529 . Hacker bisa langsung own device pakai zero-click via iMessage https://t.co/ERkllzKI67

    Post summary

    The tweet lists a few iOS CVEs and mentions a zero‑click exploit via iMessage, but provides no detailed technical or operational information.

    110301.2K
    2.7K followersView on X
  • Grok@grok
    Active Exploitation

    DarkSword is a sophisticated iOS exploit chain using multiple zero-days (like CVE-2025-31277, CVE-2025-43529) to fully compromise iPhones via a malicious Safari page—no clicks needed. It was used by state/commercial actors (targeting Ukraine, Saudi Arabia, etc.) for data theft (messages, creds, crypto wallets). A version leaked on GitHub ~3 days ago, so now any script kiddie can deploy it easily on unpatched devices. Hits iOS 18.4–18.7 (not 18.7.3+ or iOS 26.3+). Update now via Settings > General > Software Update. Lockdown Mode helps too.

    Post summary

    DarkSword is an actively exploited iOS exploit chain leveraging zero-days, with code released on GitHub; users are urged to update immediately to mitigate the vulnerability.

    000311.5K
    8.5M followersView on X
  • Paul Ducklin@duckblog
    Active Exploitation

    New iPhone patches just dropped - lots of fixes including a zero-day malware implant vulnerability that’s already being exploited. CVE-2025-14174 and CVE-2025-43529 are the in-the-wild RCE holes. You’re looking for version 26.3 *after* the update. Enjoy! https://t.co/CArVRABz9x

    Post summary

    Apple released patches for CVE‑2025‑14174 and CVE‑2025‑43529, which are actively exploited RCE vulnerabilities; users should update to version 26.3.

    01021276
    9.9K followersView on X
  • Kuncoro@0xkuncoro
    Patch

    @A_K_Mandhan Two of the WebKit bugs are already patched: CVE-2025-31277 (iOS 18.6) and CVE-2025-43529 (18.7.3 and 26.2). The kernel escape is n-day reuse of the DarkSword chain GTIG published, so anyone still below 18.7.3 stays exposed. Updating past those closes the route.

    Post summary

    The tweet confirms that two WebKit CVEs (CVE-2025-31277 and CVE-2025-43529) are already patched in iOS 18.6 and 18.7.3/26.2, respectively, and urges users to update beyond those versions to close the exposure route.

    10020656
    155 followersView on X
  • Nitesh Padghan@niteshpadghan
    Disclosure

    The technical sophistication is wild. Safari's WebContent sandbox → GPU process → mediaplaybackd → full kernel access. Each layer bypassed using a different zero-day. One exploit reported by Google was CVE-2025-43529, a garbage collection bug in JavaScriptCore's DFG JIT.

    Post summary

    The post outlines a sophisticated multi‑layer zero‑day exploit chain in Safari, referencing CVE‑2025‑43529 as a JavaScriptCore bug, but provides no PoC, exploit code, or evidence of active attacks.

    10010168
    486 followersView on X
  • Grok@grok
    Disclosure

    The exact exploitation chain for CVE-2026-20700 involves prior WebKit zero-days (CVE-2025-14174 and CVE-2025-43529) to gain initial access, then memory corruption in dyld for arbitrary code execution. It's targeted and sophisticated, per reports. Browsers like Safari (using WebKit) can be entry points for the chain, potentially granting memory write access via those linked vulns, enabling this CVE's exploit. Update immediately.

    Post summary

    The post discloses the exploitation chain for CVE‑2026‑20700, linking it to prior WebKit zero‑days and dyld memory corruption, and urges users to update immediately.

    0002057
    8.0M followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more