CVE-2025-43200: Apple Multiple Products Unspecified Vulnerability
Accessibility. An authorization issue was addressed with improved state management.
Other sources
Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
— CISA
Messages. This issue was addressed with improved checks.
— Apple
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.7.4 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 15.3.1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.3.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.3.1 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.7.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.11 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 15.8.4 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 16.7.11 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.3.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 15.8.4 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 16.7.11 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.3.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.7.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.3.1 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.3.1 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.7.4 - Compensating control
Apply vendor-provided mitigations where available; follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the affected product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-43200?
The severity of CVE-2025-43200 has not been officially rated, but it pertains to authorization issues that could lead to security vulnerabilities.
What are the affected versions for CVE-2025-43200?
CVE-2025-43200 affects Apple macOS Sequoia up to 15.3.1, macOS Sonoma up to 14.7.4, visionOS up to 2.3.1, watchOS up to 11.3.1, macOS Ventura up to 13.7.4, iPadOS up to 17.7.5, and iOS/iPadOS up to 18.3.1.
How do I fix CVE-2025-43200?
To fix CVE-2025-43200, update to the latest versions of the affected software as specified in the vendor's advisory.
What type of issue is addressed by CVE-2025-43200?
CVE-2025-43200 addresses an authorization issue through improved state management and checks.
Is there a risk of exploitation of CVE-2025-43200?
While the specific risk level of exploitation for CVE-2025-43200 is not detailed, any authorization issues can potentially be exploited by malicious actors if not addressed.