CVE-2025-43529
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
7 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.17%
probability
This CVE has a 0.17% probability
of being exploited in the next 30 days.
0%
Top 37.5th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUAF
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Google Project Zero
Patched
Dec. 12, 2025
Reported by
Google Threat Analysis Group
Root Cause Analysis
???
Exploits & PoC
SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
1
SimoesCTT/CTT-Apple-Silicon-Refraction
webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It ind
1
2 repos — triés par ⭐
Rechercher sur GitHub ↗
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover
TheHackerNews
Mar 19, 2026
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
BleepingComputer
Feb 11, 2026
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Other Devices
TheHackerNews
Feb 12, 2026
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
BleepingComputer
Dec 12, 2025
Apple discloses first actively exploited zero-day of 2026
CyberScoop
Feb 12, 2026
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
BleepingComputer
Apr 01, 2026
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
TheHackerNews
Dec 13, 2025
Signal Intelligence
Confidence
92%
EPSS
0.17%
Mentions
7
Last Seen
Apr 01, 2026
CNA Information
Analyst Note
CVE-2025-43529 is confirmed as an actively exploited zero-day affecting multiple Apple platforms with a HIGH CVSS score of 8.8. The vulnerability has been reported by Google Project Zero and documented across multiple reputable cybersecurity sources (BleepingComputer, TheHackerNews, CyberScoop), confirming in-the-wild exploitation in sophisticated attacks. Apple's official advisory and coordinated patching across iOS, iPadOS, macOS, and other platforms provide strong corroboration of the threat.
Threat Actors 5
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Mana Team
apt_group
🇨🇳 CN
Operation Triangulation
apt_group
Information theft and espionage
🇷🇺 RU
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026