CVE-2025-43531
Vulnerability Summary
Timeline
Description
A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVSS Metrics
- v3.1•LOW•Score: 3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS Trends
Current EPSS score: 0.12%• Percentile: 31%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- apple•ios and ipados
≥ unspecified, < 18.7 | ≥ unspecified, < 26.2 | < 18.7.3 | < 26.2
- apple•ipados
< 18.7.3
- apple•iphone_os
< 18.7.3 | ≥ 26.0, < 26.2
- apple•macos
≥ unspecified, < 26.2 | < 26.2
- apple•safari
≥ unspecified, < 26.2 | < 26.2
- apple•tvos
≥ unspecified, < 26.2 | < 26.2
- apple•visionos
≥ unspecified, < 26.2 | < 26.2
- apple•watchos
≥ unspecified, < 26.2 | < 26.2