Input validation error in iPadOS and Apple iOS - CVE-2025-43200
Published: June 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation in Messages application when handling photos and videos shared via an iCloud link. A remote attacker can trick the victim into opening a specially crafted media file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
visionOS
watchOS
macOS
How to mitigate CVE-2025-43200
Apple iOS - addressed in versions 18.3.1 22D8075, 15.8.4 19H390, 16.7.11 20H360
visionOS - update to 2.3.1
watchOS - update to 11.3.1
macOS - addressed in versions 13.7.4 22H420, 14.7.4 23H420, 15.3.1 24D70
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS and iPadOS
- Remote code execution in macOS Sequoia
- Remote code execution in macOS Sonoma
- Remote code execution in macOS Ventura
- Remote code execution in watchOS
- Remote code execution in Apple visionOS
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple iPadOS