CVE-2025-43541

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected Safari crash

Researchers: Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative

Attribute Value
CVE CVE-2025-43541
Bugzilla 301257
Component JSC
Bug Class TypeConfusion
Severity medium
Commit ef1aba9e847aa7b6…
Advisory Apple Advisory

Root Cause Analysis

A type confusion issue was addressed with improved state handling.

Files Changed

Source Files

  • Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp

Test Files

  • JSTests/stress/data-view-byte-length-oob-exit.js