CVE-2025-43529

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 7 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.17%
probability
This CVE has a 0.17% probability of being exploited in the next 30 days.
0% Top 37.5th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
UAF

Attack Intelligence

Google Project Zero

Patched
Dec. 12, 2025
Reported by
Google Threat Analysis Group
Root Cause Analysis
???

Exploits & PoC

SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-

CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)

1
SimoesCTT/CTT-Apple-Silicon-Refraction

webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It ind

1
2 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 0.17%
Mentions 7
Last Seen Apr 01, 2026

CNA Information

Analyst Note

CVE-2025-43529 is confirmed as an actively exploited zero-day affecting multiple Apple platforms with a HIGH CVSS score of 8.8. The vulnerability has been reported by Google Project Zero and documented across multiple reputable cybersecurity sources (BleepingComputer, TheHackerNews, CyberScoop), confirming in-the-wild exploitation in sophisticated attacks. Apple's official advisory and coordinated patching across iOS, iPadOS, macOS, and other platforms provide strong corroboration of the threat.

Threat Actors 5

APT 28
apt_group Information theft and espionage 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Mana Team
apt_group 🇨🇳 CN
Operation Triangulation
apt_group Information theft and espionage 🇷🇺 RU
APT 5
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026