CVE-2025-43200
KEVmassApple iCloud Link media-processing logic flaw exploited in targeted attacks
CISA: Apple Multiple Products Unspecified Vulnerability
CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected.
What to do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices.
| Apple iOS | Versions prior to 15.8.4, 16.7.11, and 18.3.1 (fixed in iOS 15.8.4, 16.7.11, 18.3.1) |
| Apple iPadOS | Versions prior to 15.8.4, 16.7.11, 17.7.5, and 18.3.1 (fixed in iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1) |
| Apple macOS | Versions prior to Ventura 13.7.4, Sonoma 14.7.4, and Sequoia 15.3.1 (fixed in those releases) |
| Apple visionOS | Versions prior to 2.3.1 (fixed in visionOS 2.3.1) |
| Apple watchOS | Versions prior to 11.3.1 (fixed in watchOS 11.3.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos, visionos, watchos
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N