Tools AI-Found Vulnerability Register aifv-0020
Register entry
Safari memory safety issue fixed in 26.1, credited to Google Big Sleep by Apple
- CVE
- CVE-2025-43430
- Project
- Safari
- Component
- WebKit
- Finder
- Google Big Sleep
- Autonomy
- agent finds and reproduces; a human expert reviews before reporting
- Evidence tier
- CNA credits the finder in its own advisory
- Assigner
- Apple
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
One of five Safari records Apple published on 4 November 2025 and fixed in Safari 26.1, each crediting Google Big Sleep on the Safari 26.1 security page. The sixth record of the same date, CVE-2025-43432, credits Hossein Lotfi of the Trend Micro Zero Day Initiative and stays out of this block.
Credit as recorded: "Google Big Sleep" on support.apple.com/en-us/125640; the CVE record carries no credits array. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Apple, About the security content of Safari 26.1support.apple.com/en-us/125640
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026