ZeroHour

CVE-2025-43200

KEVmass

Apple iCloud Link media-processing logic flaw exploited in targeted attacks

CISA: Apple Multiple Products Unspecified Vulnerability

CVSS 3.1
4.2 medium
EPSS
1%p62
Published
()
KEV added
AI analysis

CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected.

What to do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices.

Affected
Apple iOSVersions prior to 15.8.4, 16.7.11, and 18.3.1 (fixed in iOS 15.8.4, 16.7.11, 18.3.1)
Apple iPadOSVersions prior to 15.8.4, 16.7.11, 17.7.5, and 18.3.1 (fixed in iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1)
Apple macOSVersions prior to Ventura 13.7.4, Sonoma 14.7.4, and Sequoia 15.3.1 (fixed in those releases)
Apple visionOSVersions prior to 2.3.1 (fixed in visionOS 2.3.1)
Apple watchOSVersions prior to 11.3.1 (fixed in watchOS 11.3.1)
Estimated exposure
masshundreds of millions to ~2 billion active Apple devices on affected OS versions — Apple's announced installed base exceeds 2 billion active devices, and the affected iOS 15-18, macOS 13-15, watchOS, and visionOS branches span nearly all of that fleet at the time of the February 2025 disclosure, though only targeted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, visionos, watchos
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news