CVE-2025-43529

HIGH KEV

Apple watchOS <26.2 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-43529 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 15, 2025. EIP tracks 11 public exploits from researchers including zeroxjf, jir4vv1t, bjrjk.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2025-43529 and CVE-2025-14174, targeting WebKit and ANGLE on iOS 26.1. It demonstrates a Use-After-Free (UAF) vulnerability in JavaScriptCore and an Out-of-Bounds (OOB) write in ANGLE, with verified primitives for address leaking and type confusion.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.

Exploits (11)

nomisec WORKING POC 70 stars
by zeroxjf · poc
https://github.com/zeroxjf/WebKit-UAF-ANGLE-OOB-Analysis

This repository contains a proof-of-concept exploit for CVE-2025-43529 and CVE-2025-14174, targeting WebKit and ANGLE on iOS 26.1. It demonstrates a Use-After-Free (UAF) vulnerability in JavaScriptCore and an Out-of-Bounds (OOB) write in ANGLE, with verified primitives for address leaking and type confusion.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebKit on iOS 26.1
No auth needed
Prerequisites: iPhone 11 Pro Max with iOS 26.1 · WebKit vulnerability trigger conditions
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 62 stars
by jir4vv1t · client-side
https://github.com/jir4vv1t/CVE-2025-43529

This repository contains a detailed writeup and analysis of CVE-2025-43529, a use-after-free vulnerability in WebKit's DFG JIT compiler due to a missing StoreBarrier insertion. The vulnerability affects iOS 26.1, iPadOS 26.1, and macOS Tahoe 26.0.1.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: WebKit (iOS 26.1, iPadOS 26.1, macOS Tahoe 26.0.1)
No auth needed
Prerequisites: Target device running vulnerable iOS/iPadOS/macOS version · Ability to execute JavaScript in WebKit context
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 16 stars
by bjrjk · poc
https://github.com/bjrjk/CVE-2025-43529

This repository provides a root cause analysis for CVE-2025-43529, a UAF vulnerability in JavaScriptCore due to incorrect DFG StoreBarrierInsertionPhase. It includes a PDF analysis and references an external exploit by @jir4vv1t.

Classification
Writeup 100%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: WebKit JavaScriptCore (version not specified)
No auth needed
Prerequisites: Understanding of JavaScriptCore internals · Access to vulnerable WebKit version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 3 stars
by GenericCoding · poc
https://github.com/GenericCoding/pois0nSword

This repository provides a technical writeup detailing the exploitation of CVE-2025-43529 on iOS 26.1, focusing on achieving arbitrary read/write primitives using the Darksword scribble method. It discusses the steps involved, including bootstrapping addrof and fakeobj primitives, disabling garbage collection, and the potential for a PAC bypass and sandbox escape via ANGLE-OOB.

Classification
Writeup 90%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: iOS 26.1
No auth needed
Prerequisites: iOS 26.1 device · knowledge of memory corruption techniques · offsets for PAC bypass
devstral-2 · analyzed Jun 12, 2026 Full analysis →
nomisec WORKING POC 1 stars
by SimoesCTT · poc
https://github.com/SimoesCTT/CTT-Apple-Silicon-Refraction

This PoC exploits a Use-After-Free (UAF) vulnerability in WebKit (CVE-2025-43529) by desynchronizing the garbage collector from the GPU's Metal command buffer using a timed WebGL attack. It targets Apple Silicon devices running iOS 26.1+ or macOS Tahoe, bypassing hardware-level memory protections like EMTE and MIE.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebKit on iOS 26.1+ and macOS Tahoe (M-Series/A19 Pro Silicon)
No auth needed
Prerequisites: Victim must visit a malicious webpage · Target device must be running vulnerable iOS/macOS versions
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by GenericCoding · htmlinfoleak
https://github.com/GenericCoding/cve-2025-43529-arbitrary-ref

This repository contains a functional exploit PoC for CVE-2025-43529, demonstrating a UAF (Use-After-Free) vulnerability in WebKit on iOS 26.1. The exploit leverages memory corruption to achieve arbitrary read/write primitives, though it is blocked by PAC (Pointer Authentication Code) protections.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: WebKit on iOS 26.1
No auth needed
Prerequisites: iOS 26.1 device · WebKit browser context
devstral-2 · analyzed Jun 11, 2026 Full analysis →
github WRITEUP
by stationedK-06 · poc
https://github.com/stationedK-06/DarkSword_analysis

This repository provides a static analysis of the DarkSword iOS WebKit exploit chain, focusing on CVE-2025-31277 and CVE-2025-43529. It includes references to external sources and aims to document the exploit chain's delivery, staging, and breakdown for educational purposes.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: iOS WebKit
No auth needed
Prerequisites: Access to the referenced exploit chain sources · Understanding of iOS WebKit vulnerabilities
devstral-2 · analyzed May 01, 2026 Full analysis →
nomisec STUB
by kmeps4 · poc
https://github.com/kmeps4/bugtest

The repository contains only a minimal README with a CVE reference and no functional exploit code or technical details. It appears to be a placeholder or incomplete project.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Mar 02, 2026 Full analysis →
nomisec WRITEUP
by SgtBattenHA · poc
https://github.com/SgtBattenHA/Analysis

The repository appears to be a writeup or documentation for a project called 'telegram,' a minimalist bookmarking application. No exploit code or proof-of-concept is present in the provided files.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: telegram (a bookmarking application)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SUSPICIOUS
by sakyu7 · poc
https://github.com/sakyu7/sakyu7.github.io

The repository lacks actual exploit code or technical analysis, instead directing users to external downloads via GitHub releases. The README is marketing-focused with no substantive details about the vulnerabilities.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: iOS Safari (WebKit) and ANGLE
No auth needed
Prerequisites: none specified
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by SimoesCTT · poc
https://github.com/SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-

This is a JavaScript-based PoC for CVE-2025-43529, targeting a WebKit use-after-free vulnerability in iOS Safari. It uses a temporal resonance technique to exploit memory corruption for RCE.

Classification
Working Poc 85%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: iOS Safari (WebKit)
No auth needed
Prerequisites: iOS device with vulnerable Safari version · Access to target's browsing session
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125884
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125885
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125886
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125889
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125890
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125891
Release Notes, Vendor Advisory
https://support.apple.com/en-us/125892

Scores

CVSS v3 8.8
EPSS 0.0800
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-12-15
VulnCheck KEV 2025-12-12
ENISA EUVD EUVD-2025-203963
CWE
CWE-416
Status published
Products (14)
Apple/iOS and iPadOS < 18.7.3
Apple/iOS and iPadOS < 26.2
apple/ipados < 18.7.3
apple/iphone_os < 18.7.3
apple/macos < 26.2
Apple/macOS < 26.2
apple/safari < 26.2
Apple/Safari < 26.2
apple/tvos < 26.2
Apple/tvOS < 26.2
... and 4 more
Published Dec 17, 2025
KEV Added Dec 15, 2025
Tracked Since Feb 18, 2026