CVE-2025-43205: Input Validation
Published Mar 31, 2025
·Updated
Accessibility. A logging issue was addressed with improved data redaction.
Credit
Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dominik Rath, Martin Kreichgauer(Google Chrome), Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, Google Threat Analysis Group, wac(Trend Micro Zero Day Initiative), pattern-f@@pattern_F_, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), an anonymous researcher, Uri Katz (Oligo Security), CVE-2024-9681, Andr.Ess, Kirin@@Pwnrin, LFY@@secsys(Fudan University), Anonymous(Trend Micro Zero Day Initiative), Wang Yu(Cyberserval), Michael (Biscuit) Thomas - @social.lol@@biscuit, CVE-2024-48958, CVE-2025-27113, CVE-2024-56171, Alex Radocea(Supernetworks), Dave G.(Supernetworks), 风沐云烟@@binary_fmyy, Minghao Lin@@Y1nKoc, Jimmy, Mickey Jin@@patch1t, @@RenwaX23, Syarif Muhammad Sajjad, Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Halle Winkler, Politepix theoffcuts.org, Andrew James Gonzalez, Bohdan Stasiuk@@bohdan_stasiuk, Apple, Gary Kwong, Paul Bakker(ParagonERP), Francisco Alonso@@revskills, rheza@@ginggilBesel, Ron Masas(BREAKPOINT), Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Jaydev Ahire, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Lehan Dilusha@@zafer, Wojciech Regula(SecuRing), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), CVE-2025-24085, Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Stephan Casas, Gergely Kalman@@gergely_kalman, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), Manuel Fernandez (Stackhopper Security), Murray Mike(Trend Micro Zero Day Initiative), ABC Research s.r.o., Ian Beer(Google Project Zero), Joseph Ravichandran@@0xjprx(MIT CSAIL), Kenneth Chew, Paweł Płatek (Trail(Bits), 风沐云烟@@binary_fmyy(Supernetworks), Minghao Lin@@Y1nKoc(Supernetworks), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, Noah Gregory (wts.dev), Arsenii Kostromin (0x3c3e), Dolf Hoegaerts, Michiel Devliegere, Richard Hyunho Im with routezero.security@@richeeta, zbleet(QI), Csaba Fitzl@@theevilbit(OffSec), 风沐云烟 (binary_fmyy)(DBAppSecurity's WeBin lab), Minghao Lin@@Y1nKoc(DBAppSecurity's WeBin lab), Zhongquan Li@@Guluisacat, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH), mzzzz__, Muhammad Zaid Ghifari (Mr.ZheeV), Kalimantan Utara, Florian Draschbacher, Jax Reissner, Dalibor Milanovic, Abhay Kailasia@@abhay_kailasia(C), Chi Yuan Chang(ZUSO ART), taikosoup, Zhongcheng Li(IES Red Team of ByteDance), Junsung <3(Trend Micro Zero Day Initiative), Lukas Bernhard, Tashita Software Security, Xiangwei Zhang(Tencent Security YUNDING LAB), linjy(HKUS3Lab), chluo(WHUSecLab), Brendon Tiszka(Google Project Zero), Ian Mckay@@iann0036, luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Murray Mike, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Ye Zhang@@VAR10CK(Baidu Security), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), CVE-2023-27043, Yiğit Can YILMAZ@@yilmazcanyigit, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Pedro José Pereira Vieito / pvieito.com)@@pvieito
Affected Software
14 affected componentsFixes available
Apple macOS Sonoma<14.7.5
14.7.5
Apple macOS Ventura<13.7.5
13.7.5
Apple iPadOS<17.7.6
17.7.6
Apple macOS Sequoia<15.4
15.4
Apple visionOS<2.4
2.4
Apple tvOS<18.4
18.4
Apple WatchOS<11.4
11.4
Apple iOS<18.4
18.4
Apple iPadOS<18.4
18.4
Apple iPadOS<18.4
Apple iPhone OS<18.4
Apple tvOS<18.4
Apple visionOS<2.4
Apple WatchOS<11.4
Event History
Mar 31, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Apr 1, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Nov 12, 2025
CVE Published
via MITRE·12:20 AM
Data Sourced
via MITRE·12:20 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43205?
CVE-2025-43205 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2025-43205?
To fix CVE-2025-43205, update your affected Apple products to the latest versions specified in the vendor's advisory.
3
What products are affected by CVE-2025-43205?
CVE-2025-43205 affects Apple WatchOS, visionOS, macOS Sonoma, iOS, iPadOS, macOS Ventura, and tvOS.
4
What types of issues does CVE-2025-43205 address?
CVE-2025-43205 addresses accessibility, logging, data access restrictions, and permissions issues.
5
Is there a specific version required to mitigate CVE-2025-43205?
Yes, updates to versions 11.4 for watchOS, 2.4 for visionOS, and other specific versions for macOS and iOS products are required to mitigate CVE-2025-43205.