KEVIntel
5.5
CVSS
Medium

CVE-2025-43520

PUBLISHED

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS...

1 day faster than CISA KEV

Exploited in the wild Low complexity No user interaction
Vendor
Apple
Product
iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published
Dec 12, 2025
EPSS
0.3% · 50% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

macos ios cisa

Weaknesses (CWE)

  • Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CVSS scores

CVSS v3.1 5.5 Medium

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Exploitation status

Exploited in the wild

Recorded 2026-06-01 12:25:49 UTC · CVE

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2026-06-01 12:25 UTC
CISA 2026-06-02 14:02 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • KEV confirmed by CISA