CVE-2025-43265
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may disclose internal states of the app
Researchers: HexRabbit (@h3xr4bb1t) from DEVCORE Research Team
| Attribute | Value |
|---|---|
| CVE | CVE-2025-43265 |
| Bugzilla | 294182 |
| Component | JSC |
| Bug Class | OOB |
| Severity | medium |
| Commit | d96ab2fa64c62763… |
| Advisory | Apple Advisory |
Root Cause Analysis
An out-of-bounds read was addressed with improved input validation.
Files Changed
Source Files
Source/JavaScriptCore/yarr/YarrJIT.cpp