Security features bypass in macOS - CVE-2025-43496

 

Security features bypass in macOS - CVE-2025-43496

Published: November 4, 2025


Vulnerability identifier: #VU118050
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43496
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a missing logic in Mail Drafts when working with email messages. A remote attacker can force the application to load remote content even when the 'Load Remote Images' setting is turned off.


Affected software

macOS
visionOS
iPadOS
Apple iOS
watchOS

How to mitigate CVE-2025-43496

Install updates from vendor's website.

macOS - addressed in versions 26.1 25B78, 15.7.2 24G325
visionOS - update to 26.1
iPadOS - addressed in versions 18.7.2 22H124, 26.1 23B85
Apple iOS - addressed in versions 18.7.2 22H124, 26.1 23B85
watchOS - update to 26.1 23S37

External References

Related Security Bulletins