CVE-2025-43280: Input Validation
Accessibility. A logic issue was addressed with improved checks.
Other sources
Accessibility. The issue was addressed by adding additional logic.
— Apple
afclip. The issue was addressed with improved memory handling.
— Apple
CFNetwork. A denial-of-service issue was addressed with improved input validation.
— Apple
CoreAudio. The issue was addressed with improved memory handling.
— Apple
CoreMedia Playback. The issue was addressed with additional permissions checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31229
- CVE-2025-43217
- CVE-2025-43186
- CVE-2025-43223
- CVE-2025-43277
- CVE-2025-43210
- CVE-2025-43230
- CVE-2025-43209
- CVE-2025-43226
- CVE-2025-43282
- CVE-2025-43202
- CVE-2025-7425
- CVE-2025-7424
- CVE-2025-31276
- CVE-2025-43280
- CVE-2025-43234
- CVE-2025-43224
- CVE-2025-43221
- CVE-2025-31281
- CVE-2025-6965
- CVE-2025-43228
- CVE-2025-43227
- CVE-2025-31278
- CVE-2025-31277
- CVE-2025-31273
- CVE-2025-43214
- CVE-2025-43213
- CVE-2025-43212
- CVE-2025-43211
- CVE-2025-43265
- CVE-2025-43216
- CVE-2025-6558
Frequently Asked Questions
What is the severity of CVE-2025-43280?
CVE-2025-43280 has a high severity rating due to the potential for unauthorized exposure of remote images in Lockdown Mode.
How do I fix CVE-2025-43280?
To address CVE-2025-43280, update your device to iOS 18.6 or iPadOS 18.6.
What does CVE-2025-43280 affect?
CVE-2025-43280 affects Apple iOS and iPadOS prior to version 18.6.
What type of vulnerability is CVE-2025-43280?
CVE-2025-43280 is a remote image loading vulnerability that can expose sensitive information.
Can CVE-2025-43280 be exploited without user interaction?
Yes, CVE-2025-43280 can be exploited when forwarding emails without user interaction in Lockdown Mode.