Junglewise Threat Intelligence

CVE-2025-43510: Apple Multiple Products improper locking in shared memory

CVE-2025-43510 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-03-20

Executive brief

A security vulnerability exists in Apple's operating systems, including those for iPhones, Macs, and Apple Watches, that could allow a malicious app to interfere with other running programs. By exploiting a flaw in how the system manages shared memory, an attacker could potentially access or modify sensitive data belonging to other applications. This issue has been observed being used in targeted attacks in the wild.

Technical details

An improper locking vulnerability (CWE-667) exists in multiple Apple operating systems due to insufficient lock state checking during memory management. A local attacker can exploit this by running a malicious application that manipulates memory shared between processes, leading to memory corruption. This flaw can be used as part of an exploit chain to achieve unauthorized data access or elevated privileges. The issue has been addressed by improving lock state validation across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This vulnerability is confirmed to have been exploited in the wild.

Affected products

  • Apple iOS and iPadOS Before 18.7.2, and 26.0
  • Apple macOS Sequoia Before 15.7.2
  • Apple macOS Sonoma Before 14.8.2
  • Apple macOS Tahoe Before 26.1
  • Apple tvOS Before 26.1
  • Apple visionOS Before 26.1
  • Apple watchOS Before 26.1

Timeline

  • 2025-12-18: disclosed: Initial analysis by NIST
  • 2026-03-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-03-20: advisory: NVD advisory published

Related threats