CVE-2025-43277: Input Validation
Published Jul 29, 2025
·Updated
Accessibility. A logic issue was addressed with improved checks.
Credit
ABC Research s.r.o., Mickey Jin@@patch1t, Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), Zhongquan Li@@Guluisacat, @@zlluny(Trend Zero Day Initiative), Google's Threat Analysis Group, Seo Hyun-gyu@@wh1te4ever, Minghao Lin@@Y1nKoc, 风 (binaryfmyy), BochengXiang@@Crispr, YingQi Shi@@Mas0nShi, Dora Orak, an anonymous researcher, Wang Yu(Cyberserval), Keisuke Hosoda, Viktor Oreshkin, Mickey Jin@@patch1t(Fudan University), Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Nathaniel Oh@@calysteon, Hikerell (Loadshine Lab), Rodolphe Brunetti@@eisw0lf(Lupus Nova), Dawuge(Shuffle Team), CVE-2025-40909, Zhongcheng Li(IES Red Team of ByteDance), CVE-2024-27280, Ye Zhang(Baidu Security), pattern-f@@pattern_F_, @@zlluny, 정답이 아닌 해답, Kirin@@Pwnrin(Computer Science), Cristian Dinca(Computer Science), Romania, Noah Gregory (wts.dev), Justin Elliot Fu, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Chi Yuan Chang(ZUSO ART), taikosoup, Gary Kwong(Trend Micro Zero Day Initiative), CVE-2025-43226, Christian Kohlschütter, Sergei Glazunov(Google Project Zero), Ivan Fratric(Google Project Zero), Vlad Stolyarov(Google's Threat Analysis Group), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), CVE-2025-6965, Gilad Moav, Yehuda Afek, Anat Bremler-Barr, Amit Klein, Yuhao Hu, Yan Kang, Chenggang Wu, Xiaojie Wei, shandikri(Trend Micro Zero Day Initiative), Google V8 Security Team, Nan Wang@@eternalsakura13, Ziling Chen, HexRabbit@@h3xr4bb1t(DEVCORE Research Team), Ignacio Sanmillan@@ulexec, Clément Lecigne(Google's Threat Analysis Group), Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Wong Wee Xiang, Himanshu Bharti@@Xpl0itme, Brian Carpenter, Jaydev Ahire, MRHAX, Aditya Rana, Seo Hyun-gyu@@wh1te4ever(Xiaomi), Dora Orak(Xiaomi), Minghao Lin@@Y1nKoc(Xiaomi), XiLong Zhang@@Resery4(Xiaomi), noir@@ROIS, fmyy (@风沐云烟), 风沐云烟@@binary_fmyy, Gergely Kalman@@gergely_kalman, 2ourc3 | Salim Largo, Anonymous(Trend Micro Zero Day Initiative), Willey Lin, Arsenii Kostromin (0x3c3e), Pyrophoria, Kirin@@Pwnrin, Minghao Lin, Jiaxun Zhu, Koh M. Nakagawa@@tsunek0h(Kandji), an anonymous researcher(Loadshine Lab), Hikerell(Loadshine Lab), Wojciech Regula(SecuRing), Yuebin Sun@@yuebinsun2020, Shang-De Jiang(CyCraft Technology), Kazma Ye(CyCraft Technology), Nikolai Skliarenko(Trend Micro Zero Day Initiative), Keith Yeo@@kyeojy(Team Orca of Sea Security), Martin Bajanik(Fingerprint), Ammar Askar, Syarif Muhammad Sajjad, Martti Hütt, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Ryan Dowd@@_rdowd
Affected Software
8 affected componentsFixes available
Apple WatchOS<11.6
11.6
Apple iOS<18.6
18.6
Apple iPadOS<18.6
18.6
Apple tvOS<18.6
18.6
Apple visionOS<2.6
2.6
Apple macOS Sequoia<15.6
15.6
Apple macOS Sonoma<14.8
14.8
Apple macOS<14.8
Event History
Jul 29, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
CVE Published
via MITRE·11:29 PM
Data Sourced
via MITRE·11:29 PM
DescriptionWeakness
Jul 30, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 15, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43277?
CVE-2025-43277 has a moderate severity level due to various logic and race condition issues.
2
How do I fix CVE-2025-43277?
To fix CVE-2025-43277, users should upgrade their affected Apple devices to the latest version specified in the advisory.
3
What products are affected by CVE-2025-43277?
CVE-2025-43277 affects multiple Apple products including watchOS, macOS Sequoia, iOS, iPadOS, tvOS, and visionOS up to specific versions.
4
What type of vulnerabilities are involved in CVE-2025-43277?
CVE-2025-43277 involves logic issues, path handling issues, and improved memory handling vulnerabilities.
5
Is there a specific version of Apple software to avoid due to CVE-2025-43277?
Yes, it is recommended to avoid the affected versions of Apple software listed in the CVE-2025-43277 advisory.