CVE-2025-43520

Analyzed
Published: 12 Dec 2025, 20:56
Last modified:21 Mar 2026, 04:01

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7.1 HIGH
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Dec 2025, 20:56
Published
Vulnerability first disclosed
20 Mar 2026, 00:00
Added to CISA KEV
Apple Multiple Products Classic Buffer Overflow Vulnerability
21 Mar 2026, 04:01
Last Modified
Vulnerability information updated
03 Apr 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 3%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

  • CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Affected Systems

  • appleios and ipados

    ≥ unspecified, < 26.1 | ≥ unspecified, < 18.7

  • appleipados

    ≥ 26.0, < 26.1 | < 18.7.2 | 26.0

  • appleiphone_os

    ≥ 26.0, < 26.1 | < 18.7.2 | 26.0

  • applemacos

    < 14.8.2 | ≥ 26.0, < 26.1 | ≥ 14.0, < 14.8.2 | ≥ 15.0, < 15.7.2 | 26.0 | ≥ unspecified, < 14.8 | ≥ unspecified, < 26.1 | ≥ unspecified, < 15.7

  • appletvos

    < 26.1 | ≥ unspecified, < 26.1

  • applevisionos

    < 26.1 | ≥ unspecified, < 26.1

  • applewatchos

    < 26.1 | ≥ unspecified, < 26.1

References (10)