CVE-2025-43223

7.5

Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS

A vulnerability in multiple Apple operating systems allows a non-privileged user to modify restricted network settings, leading to a potential denial-of-service condition.

Executive summary

Multiple Apple operating systems are vulnerable to a denial-of-service flaw that permits non-privileged users to modify restricted network settings, posing a significant risk to system availability.

Vulnerability

This flaw involves improper input validation that allows a non-privileged user to alter restricted network configurations. The vulnerability is exploitable by an unauthenticated attacker via a network vector, as indicated by the CVSS vector.

Business impact

The ability for a non-privileged user to modify restricted network settings can lead to unauthorized network disruption or complete loss of connectivity for the affected device. With a CVSS score of 7.5, this high-severity vulnerability threatens business continuity by potentially rendering critical mobile and desktop infrastructure unreachable.

Remediation

Immediate Action: Update all affected Apple devices to the latest versions including iOS 18.6, iPadOS 18.6, iPadOS 17.7.9, macOS 15.6, 14.7.7, 13.7.7, tvOS 18.6, visionOS 2.6, and watchOS 11.6.

Proactive Monitoring: Monitor network traffic for unexpected configuration changes or sudden drops in device connectivity that may indicate exploitation attempts.

Compensating Controls: Implement device management policies to restrict non-essential network access and utilize mobile device management (MDM) solutions to enforce standardized network configurations across the fleet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the broad impact across Apple's ecosystem and the potential for network-based disruption, immediate patching is required. Organizations should prioritize the deployment of these security updates to all managed endpoints to prevent unauthorized network configuration changes and ensure system stability.

More Apple CVEs

Sources