State Issues in macOS - CVE-2025-43359
Published: September 16, 2025
Vulnerability identifier: #VU115335
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43359
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to a log error within the OS kernel. A UDP server socket bound to a local interface may become bound to all interfaces exposing services on the Internet.
Affected software
macOS
visionOS
watchOS
tvOS
iPadOS
Apple iOS
visionOS
watchOS
tvOS
iPadOS
Apple iOS
How to mitigate CVE-2025-43359
Install updates from vendor's website.
macOS - addressed in versions 15.7 24G222, 14.8 23J21, 26.0 25A354
visionOS - update to 26.0 23M336
watchOS - update to 26.0 23R352
tvOS - update to 26.0 23J353
iPadOS - addressed in versions 18.7 22H20, 26.0 23A341
Apple iOS - addressed in versions 18.7 22H20, 26.0 23A341
visionOS - update to 26.0 23M336
watchOS - update to 26.0 23R352
tvOS - update to 26.0 23J353
iPadOS - addressed in versions 18.7 22H20, 26.0 23A341
Apple iOS - addressed in versions 18.7 22H20, 26.0 23A341
External References
Related Security Bulletins
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS