CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in watchOS 11.3.1, macOS Ventura 13.7.4, iOS 15.8.4 and iPadOS 15.8.4, iOS...

4.8 CVSS

Description

This issue was addressed with improved checks. This issue is fixed in watchOS 11.3.1, macOS Ventura 13.7.4, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iPadOS 17.7.5, visionOS 2.3.1, macOS Sequoia 15.3.1, iOS 18.3.1 and iPadOS 18.3.1, macOS Sonoma 14.7.4. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Known Exploited

🚨 Marked as known exploited on June 16th, 2025 (14 days ago).

Classification

CVE ID: CVE-2025-43200

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Problem Types

A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Affected Products

Vendor: Apple

Product: iOS and iPadOS, macOS, iPadOS, watchOS, visionOS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.76% (probability of being exploited)

EPSS Percentile: 72.28% (scored less or equal to compared to others)

EPSS Date: 2025-06-30 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-43200
https://support.apple.com/en-us/122346
https://support.apple.com/en-us/122901
https://support.apple.com/en-us/122900
https://support.apple.com/en-us/122173
https://support.apple.com/en-us/122903
https://support.apple.com/en-us/122345
https://support.apple.com/en-us/122902
https://support.apple.com/en-us/122174
https://support.apple.com/en-us/122904

Timeline