CVE-2025-43184: Input Validation

Published Mar 31, 2025
·
Updated

Accessibility. A logging issue was addressed with improved data redaction.

Other sources

AccountPolicy. This issue was addressed by removing the vulnerable code.

Apple

Admin Framework. A path handling issue was addressed with improved validation.

Apple

afclip. The issue was addressed with improved memory handling.

Apple

AirDrop. A permissions issue was addressed with additional restrictions.

Apple

AirPlay. A null pointer dereference was addressed with improved input validation.

Apple

Credit

Ryan Dowd@@_rdowd, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), ABC Research s.r.o., Mickey Jin@@patch1t, Noah Gregory (wts.dev), Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), an anonymous researcher, Gergely Kalman@@gergely_kalman, 风沐云烟@@binary_fmyy, Minghao Lin@@Y1nKoc, 2ourc3 | Salim Largo, Dawuge(Shuffle Team), Anonymous(Trend Micro Zero Day Initiative), Gary Kwong(Trend Micro Zero Day Initiative), CVE-2025-43226, Christian Kohlschütter, Ivan Fratric(Google Project Zero), Pyrophoria, Csaba Fitzl@@theevilbit(Kandji), Minghao Lin, Jiaxun Zhu, Kirin@@Pwnrin, Zhongquan Li@@Guluisacat, Koh M. Nakagawa@@tsunek0h(Kandji), Wojciech Regula(SecuRing), Yuebin Sun@@yuebinsun2020, Shang-De Jiang(CyCraft Technology), Kazma Ye(CyCraft Technology), Nikolai Skliarenko(Trend Micro Zero Day Initiative), Mickey Jin@@patch1t(Team Orca of Sea Security), Keith Yeo@@kyeojy(Team Orca of Sea Security), Martti Hütt, Tony Iskow@@Tybbow, Zhongcheng Li(IES Red Team of ByteDance), Ron Masas(BREAKPOINT), Uri Katz (Oligo Security), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Bohdan Stasiuk@@bohdan_stasiuk, Jeffrey Hofmann, Dominik Rath, Martin Kreichgauer(Google Chrome), Ian Mckay@@iann0036, Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, Google Threat Analysis Group, wac(Trend Micro Zero Day Initiative), Nolan Astrein(Kandji), pattern-f@@pattern_F_, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Stephan Casas, CVE-2024-9681, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Andr.Ess, LFY@@secsys(Fudan University), Manuel Fernandez (Stackhopper Security), Wang Yu(Cyberserval), Murray Mike, mzzzz__, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Ye Zhang@@VAR10CK(Baidu Security), Dave G.(Supernetworks), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), Ian Beer(Google Project Zero), Joseph Ravichandran@@0xjprx(MIT CSAIL), Kenneth Chew, CVE-2024-48958, Paweł Płatek (Trail(Bits), CVE-2025-27113, CVE-2024-56171, Alex Radocea(Supernetworks), Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Alhour@@NSAntoine, Jimmy, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, CVE-2023-27043, Jaydev Ahire, @@RenwaX23, Syarif Muhammad Sajjad, Yiğit Can YILMAZ@@yilmazcanyigit, Arsenii Kostromin (0x3c3e), Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Rodolphe Brunetti@@eisw0lf(Lupus Nova), Halle Winkler, Politepix theoffcuts.org, Dolf Hoegaerts, Michiel Devliegere, Andrew James Gonzalez, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, Richard Hyunho Im with routezero.security@@richeeta, Dave G., zbleet(QI), Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Pedro José Pereira Vieito / pvieito.com)@@pvieito, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Gary Kwong, Paul Bakker(ParagonERP), Francisco Alonso@@revskills, rheza@@ginggilBesel, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH)

Affected Software

6 affected componentsFixes available
Apple macOS Ventura<13.7.7
13.7.7
Apple macOS Sonoma<14.7.7
14.7.7
Apple macOS<13.7.7
Apple macOS>=14.0<14.7.7
Apple macOS>=15.0<15.4
Apple macOS Sequoia<15.4
15.4

Event History

Mar 31, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Jul 29, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·11:28 PM
Data Sourced
via MITRE·11:28 PM
DescriptionWeakness
Jul 30, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-43184?

CVE-2025-43184 has been rated as a high severity vulnerability due to its potential impact on system integrity.

2

How do I fix CVE-2025-43184?

To fix CVE-2025-43184, update your macOS to version 13.7.7 or 14.7.7 or later, as applicable.

3

What systems are affected by CVE-2025-43184?

CVE-2025-43184 affects Apple macOS Ventura versions up to 13.7.7 and macOS Sonoma versions up to 14.7.7.

4

What type of vulnerability is CVE-2025-43184?

CVE-2025-43184 is a path handling issue related to memory and state management.

5

Is there a known workaround for CVE-2025-43184?

There are no known workarounds for CVE-2025-43184, so the best course of action is to apply the recommended updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203