cbcvebase.
CVE-2025-43510
published 2025-12-12

CVE-2025-43510: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…

PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-03
Exploited in the wild
EPSS
0.36%
27.7th percentile
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.

Affected

23 ranges
VendorProductVersion rangeFixed in
appleios_18.7.2_and_ipados
appleios_26.1_and_ipados
appleios_and_ipados< 18.7.218.7.2
appleios_and_ipados< 26.126.1
appleipados< 18.7.218.7.2
appleipados
appleiphone_os< 18.7.218.7.2
appleiphone_os
applemacos< 14.8.214.8.2
applemacos< 15.7.215.7.2
applemacos< 26.126.1
applemacos
applemacos>= 14.0 < 14.8.214.8.2
applemacos>= 15.0 < 15.7.215.7.2
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
appletvos< 26.126.1
appletvos
applevisionos< 26.126.1
applevisionos
applewatchos< 26.126.1
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

otherDarkSword iOS exploit kit
otherCoruna iOS exploit kit
  • CVE-2025-43510 is exploited as part of the DarkSword iOS exploit kit; monitor for malicious applications causing unexpected cross-process memory changes on Apple kernel (Kernel component, improper locking).
  • DarkSword wipes temporary files and exits after data theft — forensic artifacts may be minimal; look for short-lived processes and rapid file deletion on iOS devices.
  • Exploitation observed via watering-hole attacks on compromised Ukrainian websites (e-commerce, industrial equipment, local services); monitor for drive-by iOS exploitation from such site categories.
  • Threat actors UNC6748 (customer of Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage) are linked to DarkSword exploitation of CVE-2025-43510; use these cluster identifiers for threat-actor-based hunting.
  • CVE-2025-43510 is chained with CVE-2025-31277 and CVE-2025-43520 in the DarkSword exploit kit; detections should consider all three CVEs together as a combined exploitation chain.
  • Lookout associates DarkSword infrastructure with Coruna attack infrastructure; cross-reference network indicators from Coruna investigations when hunting for CVE-2025-43510 exploitation.
  • ·CVE-2025-43510 affects Apple Kernel across a wide range of products; patching scope is broad and must cover all listed platforms.
  • ·CISA remediation deadline is April 3, 2026 for FCEB agencies; BOD 22-01 applies only to federal agencies but CISA urges all defenders to prioritize patching.
  • ·The DarkSword exploit kit uses 6 vulnerabilities in total; patching only the 3 KEV-listed CVEs (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) may not fully neutralize the kit.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.