CVE-2025-43200: Apple Multiple Products Unspecified Vulnerability

Published Feb 10, 2025
·
Updated

Accessibility. An authorization issue was addressed with improved state management.

Other sources

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

CISA

Messages. This issue was addressed with improved checks.

Apple

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

MITRE

Credit

Apple, Bill Marczak(The Citizen Lab at The University of Toronto)

Affected Software

25 affected componentsFixes available
Apple macOS Sonoma<14.7.4
14.7.4
Apple macOS Sequoia<15.3.1
15.3.1
Apple visionOS<2.3.1
2.3.1
Apple WatchOS<11.3.1
11.3.1
Apple macOS Ventura<13.7.4
13.7.4
Apple iPadOS<17.7.5
17.7.5
Apple iOS<18.3.1
18.3.1
Apple iPadOS<18.3.1
18.3.1
Apple iOS<15.8.4
15.8.4
Apple iPadOS<15.8.4
15.8.4
Apple iOS<16.7.11
16.7.11
Apple iPadOS<16.7.11
16.7.11
Apple Multiple Products
Apple iPadOS<15.8.4
Apple iPadOS>=16.0<16.7.11
Apple iPadOS>=17.0<17.7.5
Apple iPadOS>=18.0<18.3.1
Apple iPhone OS<15.8.4
Apple iPhone OS>=16.0<=16.7.11
Apple iPhone OS>=17.0<=18.3.1
Apple macOS>=13.0<13.7.4
Apple macOS>=14.0<14.7.4
Apple macOS>=15.0<15.3.1
Apple visionOS<2.3.1
Apple WatchOS<11.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apple macOS to a version that resolves this vulnerability.

    Fixed in 14.7.4
  2. Upgrade

    Upgrade macOS to a version that resolves this vulnerability.

    Fixed in 15.3.1
  3. Upgrade

    Upgrade visionOS to a version that resolves this vulnerability.

    Fixed in 2.3.1
  4. Upgrade

    Upgrade Apple iOS, iPadOS, and watchOS to a version that resolves this vulnerability.

    Fixed in 11.3.1
  5. Upgrade

    Upgrade macOS Ventura to a version that resolves this vulnerability.

    Fixed in 13.7.4
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.7.5
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.3.1
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 15.8.4
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.7.11
  10. Upgrade

    Upgrade iOS to a version that resolves this vulnerability.

    Fixed in 15.8.4
  11. Upgrade

    Upgrade iOS to a version that resolves this vulnerability.

    Fixed in 16.7.11
  12. Upgrade

    Upgrade iOS to a version that resolves this vulnerability.

    Fixed in 18.3.1
  13. Upgrade

    Upgrade iPadOS to a version that resolves this vulnerability.

    Fixed in 15.8.4
  14. Upgrade

    Upgrade iPadOS to a version that resolves this vulnerability.

    Fixed in 16.7.11
  15. Upgrade

    Upgrade iPadOS to a version that resolves this vulnerability.

    Fixed in 18.3.1
  16. Upgrade

    Upgrade iPadOS to a version that resolves this vulnerability.

    Fixed in 17.7.5
  17. Upgrade

    Upgrade watchOS to a version that resolves this vulnerability.

    Fixed in 11.3.1
  18. Upgrade

    Upgrade macOS Sequoia to a version that resolves this vulnerability.

    Fixed in 15.3.1
  19. Upgrade

    Upgrade macOS Sonoma to a version that resolves this vulnerability.

    Fixed in 14.7.4
  20. Compensating control

    Apply vendor-provided mitigations where available; follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the affected product if mitigations are unavailable.

Event History

Feb 10, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Mar 31, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Jun 12, 2025
News Published
via BleepingComputer·05:42 PM
News Published
via BleepingComputer·05:43 PM
Jun 13, 2025
News Published
via The Register·03:24 PM
News Published
via The Register·03:29 PM
Jun 16, 2025
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityAffected Software
Feb 15, 57798
Event
via NVD·11:19 PM

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-43200?

The severity of CVE-2025-43200 has not been officially rated, but it pertains to authorization issues that could lead to security vulnerabilities.

2

What are the affected versions for CVE-2025-43200?

CVE-2025-43200 affects Apple macOS Sequoia up to 15.3.1, macOS Sonoma up to 14.7.4, visionOS up to 2.3.1, watchOS up to 11.3.1, macOS Ventura up to 13.7.4, iPadOS up to 17.7.5, and iOS/iPadOS up to 18.3.1.

3

How do I fix CVE-2025-43200?

To fix CVE-2025-43200, update to the latest versions of the affected software as specified in the vendor's advisory.

4

What type of issue is addressed by CVE-2025-43200?

CVE-2025-43200 addresses an authorization issue through improved state management and checks.

5

Is there a risk of exploitation of CVE-2025-43200?

While the specific risk level of exploitation for CVE-2025-43200 is not detailed, any authorization issues can potentially be exploited by malicious actors if not addressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203