CVE-2025-43520

Published Dec 12, 2025

Last updated a day ago

Overview

Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
Source
product-security@apple.com
NVD status
Analyzed
Products
ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Primary
Base score
7.1
Impact score
5.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apple Multiple Products Classic Buffer Overflow Vulnerability
Exploit added on
Mar 20, 2026
Exploit action due
Apr 3, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-120

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

23

  1. 🚨 ⚠️ ATTENTION ALL IPHONE/IPAD USERS ⚠️🚨 Vulnerabilities: CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. How it works: This isn't just one bug; it's a "chain." A user visits a malicious website or opens a crafted file, and DarkSword uses these memory corrupti

    @SteveAJ777

    21 Mar 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 ⚠️ ATTENTION ALL IPHONE/IPAD USERS ⚠️🚨 Vulnerabilities: CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. How it works: This isn't just one bug; it's a "chain." A user visits a malicious website or opens a crafted file, and DarkSword uses these memory corrupti

    @SteveAJ777

    21 Mar 2026

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 ⚠️ ATTENTION ALL IPHONE/IPAD USERS ⚠️🚨 Vulnerabilities: CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. How it works: This isn't just one bug; it's a "chain." A user visits a malicious website or opens a crafted file, and DarkSword uses these memory corrupti

    @SteveAJ777

    21 Mar 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Today CVE: CVE-2025-43520 That's the kind of thing people overlook. Buffer overflow in Apple everything. watchOS to macOS to the new Vision thing. Classic vulnerability. Classic scope.

    @EdgeDetectOps

    21 Mar 2026

    3 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件の脆弱性を追加。Apple社複数製品のCVE-2025-31277、CVE-2025-43510、CVE-2025-43520、Craft CMSのCVE-2025-32432、Laravel LivewireのCVE-202

    @__kokumoto

    21 Mar 2026

    891 Impressions

    0 Retweets

    5 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  6. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-43520 #Apple Multiple Products Classic Buffer Overflow Vulnerability https://t.co/LL2qfSTesF

    @ScyScan

    20 Mar 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️ CVE-2025-43520: Desbordamiento de Buffer en Múltiples Productos Apple Explotado Activamente Análisis técnico de la vulnerabilidad CVE-2025-43520 en Apple watchOS, iOS y más. Impacto, productos afectados y recomendaciones de mitigación para profesionale https://t.co/p

    @CiberPlanetaOrg

    20 Mar 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️ Alerta de Seguridad: Vulnerabilidad de Desbordamiento de Buffer Clásico en Múltiples Productos de Apple (CVE-2025-43520) Vulnerabilidad CWE-120 en watchOS, iOS, iPadOS, macOS, visionOS, tvOS permite a apps maliciosas causar terminación del sistema o escribir en memoria

    @CiberPlanetaOrg

    20 Mar 2026

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE Alert: CVE-2025-43520 - Apple - macOS - https://t.co/oBg69c2W3m #OSINT #ThreatIntel #CyberSecurity #cve-2025-43520 #apple #macos

    @RedPacketSec

    20 Mar 2026

    122 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. My analysis of CVE-2025-43520, the kernel vulnerability exploited by DarkSword (patched in 26.1): https://t.co/zj7HqahKYS

    @Muirey03

    20 Mar 2026

    20320 Impressions

    39 Retweets

    243 Likes

    122 Bookmarks

    2 Replies

    2 Quotes

  11. Russian 🇷🇺 UNC6353 deploys "DarkSword" iOS exploit kit targeting crypto wallets and personal data via watering hole attacks. Exploits CVE-2025-31277 through CVE-2025-43520 affecting iOS 18.4-18.7 devices. #DFIR_Radar https://t.co/Bv8ESL3HzZ

    @DFIR_Radar

    19 Mar 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations