Junglewise Threat Intelligence

CVE-2025-43202: Apple iOS and macOS memory corruption in file processing

CVE-2025-43202 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: Apple macOS, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iPhone, iPad, and Mac to address a vulnerability that occurs when processing certain files. If a user opens a specially crafted malicious file, it could lead to memory corruption, potentially allowing an attacker to compromise the device. This could result in unauthorized access to sensitive data or a complete system takeover.

Technical details

A memory corruption vulnerability exists in Apple's operating systems (iOS, iPadOS, and macOS) due to improper memory handling when processing files. The vulnerability is classified as an out-of-bounds write (CWE-787). An attacker can exploit this by tricking a user into opening a maliciously crafted file, which could lead to arbitrary code execution or system instability. The issue was addressed by improving memory handling in the affected components. Updates are available in iOS 18.6, iPadOS 18.6, and macOS Sequoia 15.6.

Affected products

  • Apple iOS Before 18.6
  • Apple iPadOS Before 18.6
  • Apple macOS Sequoia Before 15.6

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory
  • 2026-04-02: patched

References

Related threats