CVE-2025-43510
9.5 CISA KEVApple · Multiple Products (iOS, iPadOS, macOS, tvOS, visionOS, watchOS)
A memory corruption flaw in Apple products allows a malicious application to cause unauthorized changes to memory shared between processes due to improper lock state checking.
Executive summary
This critical memory corruption vulnerability in multiple Apple operating systems is actively exploited in the wild and poses a severe risk of unauthorized system access and data compromise.
Vulnerability
This is a memory corruption vulnerability within the XNU vm_map subsystem involving improper copy-on-write handling. A malicious application can trigger this flaw to manipulate memory shared between processes, requiring user interaction to execute the malicious application.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its critical nature and potential for full system compromise. Successful exploitation allows for unauthorized memory access, which can lead to complete loss of data confidentiality, integrity, and availability. Given its inclusion in the CISA KEV catalog and its role in the DarkSword exploit chain, the business risk is extreme, including the potential for surveillance or persistent unauthorized access by sophisticated threat actors.
Remediation
Immediate Action: Update all affected Apple devices to the latest versions: iOS and iPadOS 18.7.2 or 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, and 26.1 for tvOS, visionOS, and watchOS.
Proactive Monitoring: Monitor device logs for unexplained application crashes or anomalous behavior in system memory consumption, which may indicate attempted exploitation.
Compensating Controls: Ensure that Mobile Device Management (MDM) policies restrict the installation of untrusted or unauthorized applications, as the attack vector requires a malicious application to be present on the host.
Exploitation status
Public Exploit Available: Yes, as the vulnerability has been weaponized by malware such as GHOSTBLADE and is part of the publicly leaked DarkSword exploit chain.
Analyst recommendation
Due to the critical severity and confirmed active exploitation in the wild, immediate patching is mandatory. Organizations should prioritize updating all Apple endpoints to the specified versions to mitigate the risk of compromise by state-sponsored actors and commercial surveillance vendors utilizing this exploit chain.