#VU111086 Input validation error in iPadOS and Apple iOS - CVE-2025-43200
Published: June 12, 2025
iPadOS
Apple iOS
Apple Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation in Messages application when handling photos and videos shared via an iCloud link. A remote attacker can trick the victim into opening a specially crafted media file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.