Junglewise Threat Intelligence

CVE-2025-43200: Apple Multiple Products logic issue in iCloud Link media processing

CVE-2025-43200 · Severity: critical · CVSS 4.2 · Exploited in the wild · Published 2025-06-16

Technologies: Apple macOS, Apple watchOS, Apple Visionos, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability exists in Apple's operating systems (iOS, macOS, iPadOS, watchOS, and visionOS) when handling media shared through iCloud Links. An attacker could use a specially crafted photo or video to compromise a user's device if the user interacts with the malicious link. This flaw has been reportedly used in highly targeted attacks against specific individuals, such as journalists, to deploy spyware.

Technical details

A logic issue exists in the way Apple operating systems process media content shared via iCloud Links. The vulnerability is triggered when a user interacts with a maliciously crafted photo or video file. While technical specifics of the 'logic issue' are unspecified by the vendor, it allows for unauthorized actions or data access on the target device. This vulnerability has been observed in the wild as part of a sophisticated exploit chain used to deliver mercenary spyware. Apple addressed the issue by implementing improved checks in the media processing components.

Affected products

  • Apple iOS < 15.8.4, 16.0 - 16.7.11, 17.0 - 18.3.1
  • Apple iPadOS < 15.8.4, 16.0 - 16.7.11, 17.0 - 17.7.5, 18.0 - 18.3.1
  • Apple macOS Ventura < 13.7.4, Sonoma < 14.7.4, Sequoia < 15.3.1
  • Apple visionOS < 2.3.1
  • Apple watchOS < 11.3.1

Timeline

  • 2025-06-16: disclosed
  • 2025-06-16: kev added: Added to CISA KEV catalog
  • 2025-06-16: patched: Fixed in iOS 18.3.1, macOS 15.3.1, and other concurrent releases
  • 2025-06-16: exploited: Reported as exploited in targeted attacks against individuals

Related threats