CVE-2025-43510
Vulnerability Summary
Timeline
Description
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 3%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
- CWE-667•Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Affected Systems
- apple•ios and ipados
≥ unspecified, < 26.1 | ≥ unspecified, < 18.7
- apple•ipados
< 18.7.2 | 26.0
- apple•iphone_os
< 18.7.2 | 26.0
- apple•macos
≥ 14.0, < 14.8.2 | ≥ 15.0, < 15.7.2 | 26.0 | ≥ unspecified, < 14.8 | ≥ unspecified, < 26.1 | ≥ unspecified, < 15.7
- apple•tvos
< 26.1 | ≥ unspecified, < 26.1
- apple•visionos
< 26.1 | ≥ unspecified, < 26.1
- apple•watchos
< 26.1 | ≥ unspecified, < 26.1
References (10)
- https://support.apple.com/en-us/125636
- https://support.apple.com/en-us/125637
- https://support.apple.com/en-us/125634
- https://support.apple.com/en-us/125638
- https://support.apple.com/en-us/125639
- https://support.apple.com/en-us/125635
- https://support.apple.com/en-us/125632
- https://support.apple.com/en-us/125633
- https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43510