CVE-2025-43424

7.5

Apple · iOS, iPadOS, macOS

A bounds checking error in Apple iOS, iPadOS, and macOS allows a malicious HID device to trigger an unexpected process crash.

Executive summary

A vulnerability in Apple operating systems allows a malicious HID device to cause a denial of service through process termination.

Vulnerability

This vulnerability involves a lack of sufficient bounds checking that can be exploited by an unauthenticated attacker using a malicious HID device to cause an unexpected process crash.

Business impact

The primary impact of this vulnerability is a denial of service, as an attacker can force critical processes to crash via a physical HID interface. While the CVSS score of 7.5 reflects a high severity due to the potential for service disruption, the requirement for physical proximity to an HID port limits the scope of the threat in secure environments.

Remediation

Immediate Action: Update all affected Apple devices to iOS 26.1, iPadOS 26.1, or macOS Tahoe 26.1 immediately.

Proactive Monitoring: Review system logs for unexpected process terminations or recurring errors associated with HID peripheral connections.

Compensating Controls: Restrict access to physical ports or implement hardware policies that prohibit the connection of unauthorized or untrusted HID devices to corporate workstations and mobile devices.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given that this vulnerability allows for the disruption of system stability via physical hardware interaction, administrators should prioritize the deployment of the provided patches. Ensure that all managed Apple devices are updated to the specified versions to address the underlying bounds check deficiency and prevent potential denial of service attacks.

More Apple CVEs

Sources