CVE-2025-43520
📛 CVE Title
CVE-2025-43520
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- apple
- CVSS severity
- —
- CVSS score
- —
- CVSS vector
AV:L/AC:L/Au:S/C:N/I:N/A:C- Effective score
- 5.5 / 10 MEDIUM source: NVD
- CWE(s)
- —
- Reserved
- 2025-04-16
- Published
- 2025-12-12 21:56 UTC
- Last updated
- 2026-04-02 20:11 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/43xxx/CVE-2025-43520.json
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Apple Multiple Products Classic Buffer Overflow Vulnerability
- Vendor / project
- Apple
- Product
- Multiple Products
- Date added to KEV
- 2026-03-20
- Remediation due
- 2026-04-03
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43520
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-12-12 21:15:56 UTC
- NVD last modified
- 2026-06-17 09:24:11 UTC
- NVD CVSS v3.1
- 5.5 / 10 MEDIUM source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.0040 (probability of exploitation in next 30 days)
- EPSS percentile
- 31.95% vs all CVEs — higher = more likely to be exploited, as of 2026-06-27
NVD-assigned CWE(s):
CWE-120
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-06-28 12:49 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-203153 - Assigner
- apple
- Published
- Dec 12, 2025, 8:56:25 PM
- Updated
- Apr 2, 2026, 6:11:45 PM
- EUVD base score (CVSS 3.1)
-
5.5 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - EUVD-reported EPSS
- 0.2600
- Vendors
- Apple
- Products
-
visionOS (unspecified <26.1)macOS (unspecified <15.7)iOS and iPadOS (unspecified <26.1)watchOS (unspecified <26.1)macOS (unspecified <14.8)watchOS (0 <26.1)macOS (0 <26.1)macOS (0 <14.8.2)macOS (0 <15.7.2)macOS (unspecified <26.1)tvOS (unspecified <26.1)visionOS (0 <26.1)iOS and iPadOS (0 <18.7.2)iOS and iPadOS (unspecified <18.7)iOS and iPadOS (0 <26.1)tvOS (0 <26.1)
- Aliases
-
GHSA-c46j-8p94-c85x
ENISA description: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
EUVD references (8)
- https://support.apple.com/en-us/125632
- https://support.apple.com/en-us/125633
- https://support.apple.com/en-us/125634
- https://support.apple.com/en-us/125635
- https://support.apple.com/en-us/125636
- https://support.apple.com/en-us/125637
- https://support.apple.com/en-us/125638
- https://support.apple.com/en-us/125639
Affected products (5)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apple | iOS and iPadOS |
0 (affected),
0 (affected)
|
— |
| Apple | macOS |
0 (affected),
0 (affected),
0 (affected)
|
— |
| Apple | tvOS |
0 (affected)
|
— |
| Apple | visionOS |
0 (affected)
|
— |
| Apple | watchOS |
0 (affected)
|
— |
Affected products — CPE 2.3 (9) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendor references (8)
References embedded in the original CVE record by the assigning CNA.
- https://support.apple.com/en-us/125632
- https://support.apple.com/en-us/125633
- https://support.apple.com/en-us/125634
- https://support.apple.com/en-us/125635
- https://support.apple.com/en-us/125636
- https://support.apple.com/en-us/125637
- https://support.apple.com/en-us/125638
- https://support.apple.com/en-us/125639
MITRE references (5) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://support.apple.com/en-us/125636 rapid7:support.apple.com
- http://cwe.mitre.org/data/definitions/120.html rapid7:cwe.mitre.org
- https://www.cve.org/CVERecord?id=CVE-2025-43520 rapid7:www.cve.org
- https://attackerkb.com/topics/CVE-2025-43520 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203153 rapid7:euvd.enisa.europa.eu
- https://support.apple.com/en-us/125634 rapid7:support.apple.com
- https://support.apple.com/en-us/125635 rapid7:support.apple.com
NVD-tagged references (10)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ 134c704f-9b21-4f2e-91b3-4a467353bcc0 Technical Description
- https://support.apple.com/en-us/125632 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125633 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125634 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125635 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125636 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125637 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125638 product-security@apple.com Release NotesVendor Advisory
- https://support.apple.com/en-us/125639 product-security@apple.com Release NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43520 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch . None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
2026-05-23 15:31 UTC -
web:blog.qualys.com
Oracle released its first quarterly edition of this year's Critical Patch Update. The update received patches for 378 security vulnerabilities.
2026-05-23 15:31 UTC -
web:cyberpress.org
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, issuing an urgent remediation directive for federal agencies with a due date of June 3, 2026.
2026-05-23 15:31 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-23 15:31 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-23 15:31 UTC -
web:www.esri.com
Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.
2026-05-23 15:31 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - April 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...
2026-05-23 15:31 UTC -
web:www.securityweek.com
Oracle on Tuesday announced the release of 481 new security patches as part of its April 2026 Critical Patch Update (CPU). Across the 28 product families that received security updates, more than 300 patches address vulnerabilities that are remotely exploitable without authentication.
2026-05-23 15:31 UTC -
web:www.tenable.com
Oracle addresses 171 CVEs in its second quarterly update of 2025 with 378 patches, including 40 critical updates.
2026-05-23 15:31 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-23 15:31 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-43520.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2025-43520",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-03-21T04:01:02.724402Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-03-20",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43520"
},
"type": "kev"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-03-23T13:13:35.401Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/"
},
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43520"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "iOS and iPadOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "18.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "macOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "14.8.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "15.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThan": "26.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "tvOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "visionOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"product": "watchOS",
"vendor": "Apple",
"versions": [
{
"lessThan": "26.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "A malicious application may be able to cause unexpected system termination or write kernel memory",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-02T18:11:45.764Z",
"orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
"shortName": "apple"
},
"references": [
{
"url": "https://support.apple.com/en-us/125632"
},
{
"url": "https://support.apple.com/en-us/125633"
},
{
"url": "https://support.apple.com/en-us/125634"
},
{
"url": "https://support.apple.com/en-us/125635"
},
{
"url": "https://support.apple.com/en-us/125636"
},
{
"url": "https://support.apple.com/en-us/125637"
},
{
"url": "https://support.apple.com/en-us/125638"
},
{
"url": "https://support.apple.com/en-us/125639"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
"assignerShortName": "apple",
"cveId": "CVE-2025-43520",
"datePublished": "2025-12-12T20:56:25.542Z",
"dateReserved": "2025-04-16T15:27:21.196Z",
"dateUpdated": "2026-04-02T18:11:45.764Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}