CVE-2025-43520

9.5 CISA KEV

Apple · Multiple Products

A memory corruption vulnerability in multiple Apple products allows a malicious application to cause unexpected system termination or perform unauthorized writes to kernel memory.

Executive summary

This critical memory corruption vulnerability in multiple Apple platforms is currently being exploited in the wild, posing a severe risk of kernel-level compromise.

Vulnerability

The vulnerability is a memory corruption flaw that Apple addressed through improved memory handling. A malicious application, running with low privileges, can leverage this flaw to trigger system termination or write directly to kernel memory.

Business impact

The potential for kernel memory modification represents the highest tier of security risk, as it allows attackers to bypass core operating system protections. Given the 9.5 CVSS score, this vulnerability could facilitate complete system compromise, data theft, or persistent malware installation. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog significantly elevates the urgency for all organizations using these products.

Remediation

Immediate Action: Update all affected Apple devices to the versions specified in the vendor advisory: iOS 18.7.2, iPadOS 18.7.2, iOS 26.1, iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, or watchOS 26.1 immediately.

Proactive Monitoring: Monitor device logs for signs of unexpected system crashes or kernel panics that may indicate an exploitation attempt.

Compensating Controls: Restrict the installation of untrusted applications and utilize Mobile Device Management (MDM) policies to enforce update compliance across the enterprise.

Exploitation status

Public Exploit Available: No (There is no confirmed public exploit in the available data).

Analyst recommendation

Due to the confirmed active exploitation and the ability for attackers to gain kernel-level access, this CVE must be treated as a top-priority security event. Administrators should bypass standard testing cycles to deploy the necessary patches to all managed Apple hardware immediately. Failure to address this vulnerability poses an imminent risk to organizational data and infrastructure integrity.

More Apple CVEs

Sources