Security features bypass in macOS - CVE-2025-43496
Published: November 4, 2025
Vulnerability identifier: #VU118050
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43496
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a missing logic in Mail Drafts when working with email messages. A remote attacker can force the application to load remote content even when the 'Load Remote Images' setting is turned off.
Affected software
macOS
visionOS
iPadOS
Apple iOS
watchOS
visionOS
iPadOS
Apple iOS
watchOS
How to mitigate CVE-2025-43496
Install updates from vendor's website.
macOS - addressed in versions 26.1 25B78, 15.7.2 24G325
visionOS - update to 26.1
iPadOS - addressed in versions 18.7.2 22H124, 26.1 23B85
Apple iOS - addressed in versions 18.7.2 22H124, 26.1 23B85
watchOS - update to 26.1 23S37
visionOS - update to 26.1
iPadOS - addressed in versions 18.7.2 22H124, 26.1 23B85
Apple iOS - addressed in versions 18.7.2 22H124, 26.1 23B85
watchOS - update to 26.1 23S37