HomeSecurityGoogle Big Sleep: Discovered 5 vulnerabilities in Safari's WebKit

Google Big Sleep: Discovered 5 vulnerabilities in Safari's WebKit

Google's AI cybersecurity agent , Big Sleep , has discovered five security vulnerabilities in the WebKit component used in the Safari web browser . If successfully exploited by cybercriminals, these vulnerabilities could lead to browser crashes or memory corruption.

Big Sleep Google WebKit Safari Apple

The five vulnerabilities discovered by Big Sleep

1. CVE-2025-43429: A buffer overflow vulnerability that could lead to an unexpected process crashwhen processing malicious web content (addressed through improved bounds checking).

2. CVE-2025-43430: An unspecified vulnerability that could lead to an unexpected process crashwhen processing malicious web content (addressed through improved state management).

3. CVE-2025-43431 & CVE-2025-43433: Two unspecified vulnerabilities that could lead to memory corruptionwhen processing malicious web content (addressed through improved memory management).

4. CVE-2025-43434: A use-after-free vulnerability that could lead to an unexpected crash of Safariwhen processing malicious web content (addressed through improved state management).

See also: WSUS vulnerability patch broke Hotpatching in Windows Server 2025

Apple has released updates for these vulnerabilities: iOS 26.1, iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, watchOS 26.1, visionOS 26.1, and Safari 26.1.

Google Big Sleep: Discovered 5 vulnerabilities in Safari's WebKit

Updates are available for the following devices and operating systems:

– iOS 26.1 and iPadOS 26.1: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

– macOS Tahoe 26.1: Macs running macOS Tahoe.

– tvOS 26.1: Apple TV 4K (2nd generation and later models).

– visionOS 26.1: Apple Vision Pro (all models).

– watchOS 26.1: Apple Watch Series 6 and later models.

– Safari 26.1: Macs running macOS Sonoma and macOS Sequoia.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Apple fixes multiple vulnerabilities in iOS 26.1 and iPadOS 26.1

Big Sleep, previously known as Project Naptime, is an AI agent launched by Google last year as part of a collaboration between DeepMind and Google Project Zero. The goal was to automate vulnerability discovery. Earlier this year, Google reported that the language model (LLM)-assisted framework identified a security vulnerability in SQLite (CVE-2025-6965, CVSS score: 7.2) that could be exploited by malicious actors.

See also: Progress fixes serious MOVEit Transfer vulnerability

Google Big Sleep: Discovered 5 vulnerabilities in Safari's WebKit

While none of the vulnerabilities, mentioned in recent security bulletins, have been flagged as exploitable, it is always good practice to keep devices updated to the latest version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS