Input validation error in iPadOS and Apple iOS - CVE-2025-43200

 

Input validation error in iPadOS and Apple iOS - CVE-2025-43200

Published: June 12, 2025


Vulnerability identifier: #VU111086
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43200
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation in Messages application when handling photos and videos shared via an iCloud link. A remote attacker can trick the victim into opening a specially crafted media file and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

iPadOS
Apple iOS
visionOS
watchOS
macOS

How to mitigate CVE-2025-43200

Install updates from vendor's website.

iPadOS - addressed in versions 18.3.1 22D72, 15.8.4 19H390, 16.7.11, 17.7.5
Apple iOS - addressed in versions 18.3.1 22D8075, 15.8.4 19H390, 16.7.11 20H360
visionOS - update to 2.3.1
watchOS - update to 11.3.1
macOS - addressed in versions 13.7.4 22H420, 14.7.4 23H420, 15.3.1 24D70

External References

Related Security Bulletins