CVE-2025-43200
published 2025-06-16CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS…
PriorityP279medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-07-07
Exploited in the wild
EPSS
1.01%
59.2th percentile
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.4_and_ipados | — | — |
| apple | ios_16.7.11_and_ipados | — | — |
| apple | ios_18.3.1_and_ipados | — | — |
| apple | ios_and_ipados | < 15.8.4 | 15.8.4 |
| apple | ios_and_ipados | < 16.7.11 | 16.7.11 |
| apple | ios_and_ipados | < 18.3.1 | 18.3.1 |
| apple | ipados | < 17.7.5 | 17.7.5 |
| apple | ipados | < 15.8.4 | 15.8.4 |
| apple | ipados | — | — |
| apple | ipados | >= 16.0 < 16.7.11 | 16.7.11 |
| apple | ipados | >= 17.0 < 17.7.5 | 17.7.5 |
| apple | ipados | >= 18.0 < 18.3.1 | 18.3.1 |
| apple | iphone_os | < 15.8.4 | 15.8.4 |
| apple | iphone_os | 16.0 – 16.7.11 | — |
| apple | iphone_os | 17.0 – 18.3.1 | — |
| apple | macos | < 13.7.4 | 13.7.4 |
| apple | macos | < 14.7.4 | 14.7.4 |
| apple | macos | < 15.3.1 | 15.3.1 |
| apple | macos | >= 13.0 < 13.7.4 | 13.7.4 |
| apple | macos | >= 14.0 < 14.7.4 | 14.7.4 |
| apple | macos | >= 15.0 < 15.3.1 | 15.3.1 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | visionos | < 2.3.1 | 2.3.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Post-exploitation, Graphite spyware beacons out to a C2 server. Monitor for outbound connections from iOS/macOS devices to 46.183.184.91 (EDIS Global VPS) as an indicator of compromise. ↗
- →Targeted devices were running iOS 18.2.1 at time of exploitation; devices on iOS versions prior to 18.3.1 (patched February 10) remain vulnerable. Prioritize detection/patching on unpatched iOS/iPadOS/macOS endpoints. ↗
- ·The C2 IP (46.183.184.91) was only confirmed active until April 12; infrastructure may have rotated since then. ↗
- ·Apple has not confirmed whether CVE-2025-43200 can be exploited on devices with Lockdown Mode enabled, leaving uncertainty about its effectiveness as a full mitigation. ↗
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
vulncheck4.2MEDIUM
cisa4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple Multiple Products Unspecified Vulnerability
cisa·2025-06-16·CVSS 4.2
CVE-2025-43200 [MEDIUM] Apple Multiple Products Unspecified Vulnerability
Vulnerability: Apple Multiple Products Unspecified Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/122174 ; https://support.apple.com/en-us/122173 ; https://support.apple.com/en-us/122900 ; https://support.apple.com/en-us/122901 ; https://support.apple.com/en-us/122902 ; https://support.apple.com/en-us/122903 ; https://support.apple.com/en-us/122904 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43200
Remedi
Apple
CVE-2025-43200: iOS 16.7.11 and iPadOS 16.7.11
vendor_apple·2025-03-31·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: iOS 16.7.11 and iPadOS 16.7.11
Apple Security Update: About the security content of iOS 16.7.11 and iPadOS 16.7.11
Product: iOS 16.7.11 and iPadOS
Version: 16.7.11
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: iOS 15.8.4 and iPadOS 15.8.4
vendor_apple·2025-03-31·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: iOS 15.8.4 and iPadOS 15.8.4
Apple Security Update: About the security content of iOS 15.8.4 and iPadOS 15.8.4
Product: iOS 15.8.4 and iPadOS
Version: 15.8.4
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: macOS Sequoia 15.3.1
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: macOS Sequoia 15.3.1
Apple Security Update: About the security content of macOS Sequoia 15.3.1
Product: macOS Sequoia
Version: 15.3.1
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: macOS Ventura 13.7.4
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: macOS Ventura 13.7.4
Apple Security Update: About the security content of macOS Ventura 13.7.4
Product: macOS Ventura
Version: 13.7.4
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: iPadOS 17.7.5
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: iPadOS 17.7.5
Apple Security Update: About the security content of iPadOS 17.7.5
Product: iPadOS
Version: 17.7.5
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: watchOS 11.3.1
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: watchOS 11.3.1
Apple Security Update: About the security content of watchOS 11.3.1
Product: watchOS
Version: 11.3.1
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: macOS Sonoma 14.7.4
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: macOS Sonoma 14.7.4
Apple Security Update: About the security content of macOS Sonoma 14.7.4
Product: macOS Sonoma
Version: 14.7.4
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: visionOS 2.3.1
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: visionOS 2.3.1
Apple Security Update: About the security content of visionOS 2.3.1
Product: visionOS
Version: 2.3.1
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
Apple
CVE-2025-43200: iOS 18.3.1 and iPadOS 18.3.1
vendor_apple·2025-02-10·CVSS 4.2
CVE-2025-43200 [MEDIUM] CVE-2025-43200: iOS 18.3.1 and iPadOS 18.3.1
Apple Security Update: About the security content of iOS 18.3.1 and iPadOS 18.3.1
Product: iOS 18.3.1 and iPadOS
Version: 18.3.1
CVE: CVE-2025-43200
Component: Messages
Impact: A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: This issue was addressed with improved checks.
GHSA
GHSA-whff-4x34-r5vx: This issue was addressed with improved checks
ghsa_unreviewed·2025-06-17
CVE-2025-43200 [MEDIUM] GHSA-whff-4x34-r5vx: This issue was addressed with improved checks
This issue was addressed with improved checks. This issue is fixed in watchOS 11.3.1, macOS Ventura 13.7.4, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iPadOS 17.7.5, visionOS 2.3.1, macOS Sequoia 15.3.1, iOS 18.3.1 and iPadOS 18.3.1, macOS Sonoma 14.7.4. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
VulnCheck
Apple Multiple Products Unspecified Vulnerability
vulncheck·2025·CVSS 4.2
CVE-2025-43200 [MEDIUM] Apple Multiple Products Unspecified Vulnerability
Apple Multiple Products Unspecified Vulnerability
Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.enisa.europa.eu/sites/default/
No detection rules found.
No public exploits indexed.
Krebs
Senator Chides FBI for Weak Advice on Mobile Security
blogs_krebs·2025-06-30
Senator Chides FBI for Weak Advice on Mobile Security
Agents with the Federal Bureau of Investigation (FBI) briefed Capitol Hill staff recently on hardening the security of their mobile devices, after a contacts list stolen from the personal phone of the White House Chief of Staff Susie Wiles was reportedly used to fuel a series of text messages and phone calls impersonating her to U.S. lawmakers. But in a letter this week to the FBI, one of the Senate’s most tech-savvy lawmakers says the feds aren’t doing enough to recommend more appropriate security protections that are already built into most consumer mobile devices.
A screenshot of the first page from Sen. Wyden’s letter to FBI Director Kash Patel.
On May 29, The Wall Street Journal reported that federal authorities were investigating a clandestine effort to impersonate Ms. Wiles via te
Krebs
Senator Chides FBI for Weak Advice on Mobile Security
blogs_krebs·2025-06-30
Senator Chides FBI for Weak Advice on Mobile Security
Agents with the Federal Bureau of Investigation (FBI) briefed Capitol Hill staff recently on hardening the security of their mobile devices, after a contacts list stolen from the personal phone of the White House Chief of Staff Susie Wiles was reportedly used to fuel a series of text messages and phone calls impersonating her to U.S. lawmakers. But in a letter this week to the FBI, one of the Senate’s most tech-savvy lawmakers says the feds aren’t doing enough to recommend more appropriate security protections that are already built into most consumer mobile devices.
On May 29, The Wall Street Journal reported that federal authorities were investigating a clandestine effort to impersonate Ms. Wiles via text messages and in phone calls that may have used AI to spoof her voice. According to
Bleepingcomputer
Graphite spyware used in Apple iOS zero-click attacks on journalists
blogs_bleepingcomputer·2025-06-12·CVSS 4.2
CVE-2025-43200 [MEDIUM] Graphite spyware used in Apple iOS zero-click attacks on journalists
## Graphite spyware used in Apple iOS zero-click attacks on journalists
## Bill Toulas
The attacks occurred in early 2025, and Apple sent a notification to the two victims on April 29 informing that they had been targeted by “advanced spyware.”
The threat actor used Paragon's Graphite spyware platform to target the victims' iPhone devices running iOS 18.2.1 and exploit CVE-2025-43200, which was a zero-day vulnerability at the time.
Apple describes the flaw as “a logic issue that existed when processing a maliciously crafted photo or video shared via an iCloud Link.”
The vendor addressed the vulnerability in the next iOS release, 18.3.1, on February 10, by adding improved checks. However, the CVE identifier was added earlier today to the security bulletin .
BleepingComputer has reache
https://support.apple.com/en-us/122173https://support.apple.com/en-us/122174https://support.apple.com/en-us/122345https://support.apple.com/en-us/122346https://support.apple.com/en-us/122900https://support.apple.com/en-us/122901https://support.apple.com/en-us/122902https://support.apple.com/en-us/122903https://support.apple.com/en-us/122904https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43200
2025-06-16
Published
2025-06-16
Added to CISA KEV
Exploited in the wild