← Back

CVE-2025-43200

nvd nist
Published: Jun 16, 2025Modified: Apr 3, 2026CISA KEV

JSON object

Loading...
4.2
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Affected (12)

5 products
Ipados
Iphone Os
Macos
Visionos
Watchos
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Before 15.8.4
From 16.0 to 16.7.11
From 17.0 to 17.7.5
From 18.0 to 18.3.1
Apple
Before 15.8.4
From 16.0 to 16.7.11
From 17.0 to 18.3.1
Apple
From 13.0 to 13.7.4
From 14.0 to 14.7.4
From 15.0 to 15.3.1
Before 2.3.1
Before 11.3.1

References (11)

Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.