Kernel Buffer Overflow (Memory Corruption) in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS
CISA: Apple Multiple Products Classic Buffer Overflow Vulnerability
CVSS 3.1
5.5medium
EPSS
<1%p36
Published
()
KEV added
AI analysis
CVE-2025-43520 is a classic buffer overflow (CWE-120) in the kernel of multiple Apple operating systems, a memory corruption issue that Apple resolved with improved memory handling. It is triggered locally: a malicious application already running on a vulnerable iPhone, iPad, Mac, Apple TV, Apple Vision Pro, or Apple Watch can corrupt kernel memory without user interaction or special privileges. An attacker gains the ability to write kernel memory and can cause unexpected system termination (crash/denial of service), reflected in the CVSS 5.5 score (local attack, low privileges, high availability impact). All users of Apple devices running versions earlier than the fixed releases are affected: iOS/iPadOS before 18.7.2 or 26.1, macOS Sequoia before 15.7.2, macOS Sonoma before 14.8.2, macOS Tahoe before 26.1, and tvOS, visionOS, and watchOS before 26.1. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-20 with a federal patching deadline of April 3, 2026, and press reports link the Apple bugs to the recently surfaced DarkSword iOS exploit kit, confirming exploitation in the wild.
What to do: Update every Apple device to its platform's fixed release: iOS/iPadOS 18.7.2 or 26.1; macOS Sequoia 15.7.2, Sonoma 14.8.2, or Tahoe 26.1; tvOS 26.1; visionOS 26.1; watchOS 26.1. Federal agencies must apply the updates by the BOD 22-01 deadline of April 3, 2026, and all organizations should prioritize fleet devices and BYOD endpoints that install or run untrusted applications, since exploitation requires local code execution. Check the installed OS version in device settings and treat anything below the fixed versions as vulnerable.
Affected
Apple iPhone OS (iOS)
All versions before the fixed releases; fixed in iOS 18.7.2 and iOS 26.1
Apple iPadOS
All versions before the fixed releases; fixed in iPadOS 18.7.2 and iPadOS 26.1
Apple macOS Sequoia
Versions before 15.7.2; fixed in macOS Sequoia 15.7.2
Apple macOS Sonoma
Versions before 14.8.2; fixed in macOS Sonoma 14.8.2
Apple macOS Tahoe
Versions before 26.1; fixed in macOS Tahoe 26.1
Apple tvOS
Versions before 26.1; fixed in tvOS 26.1
Apple visionOS
Versions before 26.1; fixed in visionOS 26.1
Apple watchOS
Versions before 26.1; fixed in watchOS 26.1
Estimated exposure
mass≈2 billion Apple devices potentially affected (all Apple devices running OS versions below the listed fixes) — Apple's publicly reported active installed base exceeds 2 billion devices across iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch, and any device not yet updated to the fixed OS releases is vulnerable, though exploitation requires…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Trojanized Packagist themes inject JavaScript into Vietnamese streaming sites, exploiting unpatched iPhone WebKit and kernel flaws to install spyware and steal crypto wallet seeds.
Socket researchers found 13 malicious Composer theme packages across five vendor namespaces (including vsmov, vsphim, and ophimcms) that inject JavaScript into Vietnamese movie and comic streaming sites. On iPhones running iOS 18.4-18.6.x, the injected code fires a WebKit-to-kernel exploit chain using CVE-2025-31277 and CVE-2025-43529, pivoting through the GPU process and the AppleM2ScalerCSCDriver IOKit user client to gain kernel read/write. Since around August 12, 2026 the payload also steals cryptocurrency wallet seeds and mnemonics from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX, alongside keychain databases, Wi-Fi passwords, SMS, photos, cookies, and location history, uploaded via HTTPS to rotating C2 domains. The group is believed to be Vietnamese-operated, hosts exploits on Funnull infrastructure, and Apple patched the kernel escape flaw in iOS and macOS 26.1.