Cyber Resilience

CVE-2025-43200

Apple Ipados ≤ 15.8.4

CISA KEVActive ExploitationEUVD Exploited
Published
16 June 2025
Modified
17 June 2026
KEV Added
16 June 2025
Patch / advisory
CVSS Score v3.1 4.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score 0.011 61th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2025-43200 is a medium-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 4.2 (Medium).

Operationally, ranked in the top 39% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A logic issue existed in multiple Apple operating systems when processing a maliciously crafted photo or video shared via an iCloud Link. The affected platforms include iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, and watchOS 11.3.1. The flaw was addressed through improved validation checks in these releases.

An attacker could exploit the issue by delivering a specially crafted media file through an iCloud Link, requiring user interaction and high attack complexity to achieve limited impacts on confidentiality and integrity. Apple has stated that the vulnerability may have been used in an extremely sophisticated attack targeting specific individuals.

The referenced Apple security advisories confirm that updating to the listed patched versions mitigates the risk by implementing the improved checks. No further workaround details are provided beyond installation of the fixes.

EU & UK References

Vulnerability Data

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1,…

more

watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

CWE(s)
KEV Date Added
16 June 2025

Related Threats

CVEs Like This One

CVE-2025-24085Same product: Apple Ipadosboth on KEV
CVE-2026-20700Same product: Apple Ipadosboth on KEV
CVE-2025-43520Same product: Apple Ipadosboth on KEV
CVE-2025-43510Same product: Apple Ipadosboth on KEV
CVE-2024-23225Same product: Apple Ipadosboth on KEV
CVE-2024-23296Same product: Apple Ipadosboth on KEV
CVE-2025-31200Same product: Apple Ipadosboth on KEV
CVE-2020-27950Same product: Apple Ipadosboth on KEV
CVE-2022-32894Same product: Apple Ipadosboth on KEV
CVE-2023-32434Same product: Apple Ipadosboth on KEV

Affected Assets

apple
ipados
≤ 15.8.4 · 16.0 — 16.7.11 · 17.0 — 17.7.5
apple
iphone os
≤ 15.8.4 · 16.0 — 16.7.11 · 17.0 — 18.3.1
apple
macos
13.0 — 13.7.4 · 14.0 — 14.7.4 · 15.0 — 15.3.1
apple
visionos
≤ 2.3.1
apple
watchos
≤ 11.3.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References