All findings

CVE-2025-43535, CVE-2025-46299 medium

Apple WebKit 26.2 follow-up issues credited to Google Big Sleep

Apple's iOS 26.2 and iPadOS 26.2 security content credits Google Big Sleep on additional WebKit issues, including CVE-2025-43535 and CVE-2025-46299.

Bug class
WebKit memory handling / internal-state disclosure
Affected codebase
Apple WebKit / iOS and iPadOS
Credited system
Google Big Sleep
Disclosed
January 9, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Direct Apple security advisory credits Google Big Sleep. CVE-2025-43535 is co-credited with Nan Wang; CVE-2025-46299 is credited to Google Big Sleep.

Summary

Apple’s iOS 26.2 and iPadOS 26.2 security content includes two WebKit entries that credit Google Big Sleep:

The CVE-2025-46299 entry was added on January 9, 2026, so we use that date for this index entry.

Why it matters

The follow-up matters less for any single CVE than for the continuity of the record. Big Sleep was not a one-off SQLite demonstration. By late 2025 and early 2026, upstream product advisories were repeatedly naming it in accepted WebKit security fixes.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.