CVE-2025-43510 is a high-severity memory corruption vulnerability affecting multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. It allows a malicious application to cause unexpected changes in memory shared between processes. With a CVSS score of 7.8, exploitation requires local access and user interaction but has low attack complexity, leading to high impacts on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's Known Exploited Vulnerabilities catalog and mentions of an "iOS Exploit Chain Adopted by Multiple Threat Actors." Despite active exploitation, no public exploit code has been identified, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.7.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
26.0CPE matchmatch criteria | cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:* | ||
< 18.7.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
26.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:* | ||
>= 14.0, < 14.8.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.