CVE-2025-43361: Use After Free
Published Sep 15, 2025
·Updated
Admin Framework. A logic issue was addressed with improved checks.
Credit
Michael Reeves@@IntegralPilot, Csaba Fitzl@@theevilbit(Kandji), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), @@zlluny(Trend Micro Zero Day Initiative), 이동하 (Lee Dong Ha)(SSA Lab), Keisuke Hosoda, Viktor Oreshkin, Mickey Jin@@patch1t, Dawuge(Shuffle Team), an anonymous researcher, Noah Gregory (wts.dev), CVE-2025-6965, JZ, Seo Hyun-gyu@@wh1te4ever, Luke Roberts@@rookuu, Jaydev Ahire, Big Bear, Ignacio Sanmillan@@ulexec, Mike Cardwell(grepular), Bob Lord, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Gergely Kalman@@gergely_kalman, Joseph Ravichandran@@0xjprx(MIT CSAIL), Dave G. (supernetworks.org), Zhongcheng Li(IES Red Team of ByteDance), Morris Richman@@morrisinlife, Hikerell (Loadshine Lab), 이동하 (Lee Dong Ha(BoB 14th), wac(Trend Micro Zero Day Initiative), Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), pattern-f@@pattern_F_, Ferdous Saljooki@@malwarezoo(Jamf), Murray Mike, Cristian Dinca (icmd.tech), Apple, Dave G.(supernetworks), Alex Radocea(supernetworks), Taavi Eomäe(Zone Media), Kirin@@Pwnrin, Atul R V, Asaf Cohen, CVE-2024-43398, CVE-2024-49761, CVE-2025-6442, Vivek Dhar, ASI (RM) in Border Security Force, FTR HQ BSF Kashmir, Nikolai Skliarenko(Trend Micro Zero Day Initiative), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Wang Yu(Cyberserval), Ryan Dowd@@_rdowd, Nolan Astrein(Kandji), Duy Trần@@khanhduytran0, Adwiteeya Agrawal, Romain Lebesle(Khatima), Himanshu Bharti@@Xpl0itme(Khatima), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), BynarIO AI (bynar.io), Kirin@@Pwnrin(Microsoft), Nikita Sakalouski, Rosyna Keller(Totally Not Malicious Software), Guilherme Rambo(Best Buddy Apps), Philipp Baldauf, Minghao Lin@@Y1nKoc, Lyutoon@@Lyutoon_, YingQi Shi@@Mas0n, Tom Brzezinski, Abhay Kailasia@@abhay_kailasia(C), KPC(Cisco Talos), Evan Waelde, 정답이 아닌 해답, Richard Hyunho Im@@richeeta, Pawel Wylecial(REDTEAM), Zhongquan Li@@Guluisacat, Bilal Siddiqui, Shantanu Thakur, Anonymous(Trend Micro Zero Day Initiative), Yiğit Can YILMAZ@@yilmazcanyigit, Ye Zhang@@VAR10CK(Baidu Security), Nathaniel Oh@@calysteon, Rodolphe Brunetti@@eisw0lf(Lupus Nova), LFY@@secsys(Fudan University), CVE-2025-40909, @@zlluny, CVE-2024-27280, @@RenwaX23, Ye Zhang(Baidu Security), Kirin@@Pwnrin(Computer Science), Cristian Dinca(Computer Science), Romania, Justin Elliot Fu, Pyrophoria(GrapheneOS), an anonymous researcher(GrapheneOS), James J Kalafus, Michel Migdal, ken super, ABC Research s.r.o., Mickey Jin@@patch1t(Cisco Talos), Kirin@@Pwnrin(Cisco Talos), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos)
Affected Software
15 affected componentsFixes available
Apple macOS Sequoia<15.7.2
15.7.2
Apple macOS Sonoma<14.8.2
14.8.2
Apple iPadOS<26.1
Apple iPhone OS<26.1
Apple macOS<14.8.2
Apple macOS>=15.0<15.7.2
Apple tvOS<26.1
Apple visionOS<26.1
Apple WatchOS<26.1
Apple WatchOS<26
26
Apple iOS<26
26
Apple iPadOS<26
26
Apple visionOS<26
26
Apple tvOS<26
26
Apple macOS Tahoe<26
26
Event History
Sep 15, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Nov 3, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Nov 4, 2025
CVE Published
via MITRE·01:16 AM
Data Sourced
via MITRE·01:16 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43361?
CVE-2025-43361 has been classified as a logic issue that could lead to an out-of-bounds read vulnerability.
2
How do I fix CVE-2025-43361?
To fix CVE-2025-43361, update your Apple device to the latest version available, such as tvOS 26, watchOS 26, iOS 26, iPadOS 26, macOS Sonoma 14.8.2, or macOS Sequoia 15.7.2.
3
Which Apple products are affected by CVE-2025-43361?
CVE-2025-43361 affects macOS Sequoia, macOS Sonoma, tvOS, watchOS, iOS, iPadOS, and visionOS prior to their respective fixed versions.
4
What type of vulnerability is CVE-2025-43361?
CVE-2025-43361 is categorized as a logic issue that can lead to kernel read access vulnerabilities in affected Apple software.
5
When was CVE-2025-43361 addressed by Apple?
CVE-2025-43361 was addressed with improved checks and bounds checking in software updates released by Apple for the affected products.