Aller au contenu

Fiche vulnérabilité

CVE-2025-43200 : faille exploitée apple ipados (CVSS 4.2)

Description

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

En bref

Sévérité
Moyenne (CVSS 4.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
16 juin 2025
Dernière mise à jour
24 sept. 2026

Produits concernés

  • apple ipados
  • apple iphone os
  • apple macos
  • apple visionos
  • apple watchos

Correctif et mesures

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE