CVE-2025-43520
published 2025-12-12CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…
PriorityP180medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-03
Exploited in the wild
EPSS
0.41%
33.0th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.2_and_ipados | — | — |
| apple | ios_26.1_and_ipados | — | — |
| apple | ios_and_ipados | < 18.7.2 | 18.7.2 |
| apple | ios_and_ipados | < 26.1 | 26.1 |
| apple | ipados | < 18.7.2 | 18.7.2 |
| apple | ipados | — | — |
| apple | iphone_os | < 18.7.2 | 18.7.2 |
| apple | iphone_os | — | — |
| apple | macos | < 14.8.2 | 14.8.2 |
| apple | macos | < 15.7.2 | 15.7.2 |
| apple | macos | < 26.1 | 26.1 |
| apple | macos | — | — |
| apple | macos | >= 14.0 < 14.8.2 | 14.8.2 |
| apple | macos | >= 15.0 < 15.7.2 | 15.7.2 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| apple | tvos | < 26.1 | 26.1 |
| apple | tvos | — | — |
| apple | visionos | < 26.1 | 26.1 |
| apple | visionos | — | — |
| apple | watchos | < 26.1 | 26.1 |
| apple | watchos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-43520 is exploited as part of the DarkSword iOS exploit kit in watering-hole attacks; monitor for iPhone users visiting compromised websites (e-commerce, industrial equipment, local services) particularly Ukrainian-hosted domains. ↗
- →DarkSword wipes temporary files and exits after data theft; forensic artefacts may be minimal — focus on short-lived process execution and rapid file deletion patterns on iOS devices. ↗
- →Threat actors UNC6748 (linked to Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage) are attributed DarkSword operators; use these cluster identifiers for threat-intel pivoting. ↗
- →CVE-2025-43520 affects the Kernel component; prioritise patching to iOS 18.7.2/iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and other listed OS versions to close the kernel memory-write primitive. ↗
- →CISA KEV deadline is April 3, 2026 for FCEB agencies; treat unpatched Apple devices running affected OS versions as high-priority exposure in asset inventories. ↗
- ·CVE-2025-43520 is one of six vulnerabilities chained in the DarkSword exploit kit; patching this CVE alone does not fully neutralise the kit — all six flaws (including CVE-2025-31277 and CVE-2025-43510) must be addressed. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c46j-8p94-c85x: A memory corruption issue was addressed with improved memory handling
ghsa_unreviewed·2025-12-12
CVE-2025-43520 [MEDIUM] CWE-120 GHSA-c46j-8p94-c85x: A memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
VulnCheck
Apple Multiple Products Classic Buffer Overflow Vulnerability
vulncheck·2025·CVSS 5.5
CVE-2025-43520 [MEDIUM] CWE-120 Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/; https://iverify.io/blog/darksword-ios-exploit-kit-explained; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-04-03
CISA
Apple Multiple Products Classic Buffer Overflow Vulnerability
cisa·2026-03-20·CVSS 5.5
CVE-2025-43520 [MEDIUM] CWE-120 Apple Multiple Products Classic Buffer Overflow Vulnerability
Vulnerability: Apple Multiple Products Classic Buffer Overflow Vulnerability
Affected: Apple Multiple Products
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; ht
Apple
CVE-2025-43520: iOS 18.7.2 and iPadOS 18.7.2
vendor_apple·2025-11-05·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: iOS 18.7.2 and iPadOS 18.7.2
Apple Security Update: About the security content of iOS 18.7.2 and iPadOS 18.7.2
Product: iOS 18.7.2 and iPadOS
Version: 18.7.2
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: macOS Sequoia 15.7.2
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Sequoia 15.7.2
Apple Security Update: About the security content of macOS Sequoia 15.7.2
Product: macOS Sequoia
Version: 15.7.2
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: tvOS 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: tvOS 26.1
Apple Security Update: About the security content of tvOS 26.1
Product: tvOS
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: visionOS 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: visionOS 26.1
Apple Security Update: About the security content of visionOS 26.1
Product: visionOS
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: iOS 26.1 and iPadOS 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: iOS 26.1 and iPadOS 26.1
Apple Security Update: About the security content of iOS 26.1 and iPadOS 26.1
Product: iOS 26.1 and iPadOS
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: macOS Sonoma 14.8.2
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: watchOS 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: watchOS 26.1
Apple Security Update: About the security content of watchOS 26.1
Product: watchOS
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2025-43520: macOS Tahoe 26.1
vendor_apple·2025-11-03·CVSS 5.5
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
blogs_bleepingcomputer·2026-04-01·CVSS 8.8
CVE-2025-31277 [HIGH] Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Lawrence Abrams
In March, researchers at Lookout, iVerify, and Google Threat Intelligence revealed a new "DarkSword" exploit kit that targeted iPhones running iOS 18.4 through 18.7.
The six vulnerabilities used by the DarkSword exploit kit are tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
While iOS exploits have typically been used in highly targeted spyware campaigns, this iOS exploit kit was used much more widely, including by Turkish commercial surveillance vendor PARS Defense, a threat actor tracked as UNC6748, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-stealing mal
Bleepingcomputer
CISA orders feds to patch DarkSword iOS flaws exploited attacks
blogs_bleepingcomputer·2026-03-23·CVSS 8.8
[HIGH] CISA orders feds to patch DarkSword iOS flaws exploited attacks
## CISA orders feds to patch DarkSword iOS flaws exploited attacks
## Sergiu Gatlan
DarkSword was also linked by security researchers to multiple threat groups, including UNC6748, a customer of Turkish commercial surveillance vendor PARS Defense, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-theft malware families dropped on victims' devices: a very aggressive JavaScript infostealer named GhostBlade, the GhostKnife backdoor that can exfiltrate large swaths of data, and the GhostSaber JavaScript that executes code and also steals victims' data.
Of the three, UNC6353 deployed both the DarkSword and Coruna iOS exploit kits in watering-hole attacks targeting iPhone users visiting compromised Ukrainian websites of e-co
Hackernews
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
blogs_hackernews·2026-03-21·CVSS 8.8
[HIGH] CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to patch them by April 3, 2026.
The vulnerabilities that have come under exploitation are listed below -
CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025)
CVE-2025-43510 (CVSS score: 7.8) - A
Bleepingcomputer
New DarkSword iOS exploit used in infostealer attack on iPhones
blogs_bleepingcomputer·2026-03-18·CVSS 8.8
CVE-2025-31277 [HIGH] New DarkSword iOS exploit used in infostealer attack on iPhones
## New DarkSword iOS exploit used in infostealer attack on iPhones
## Bill Toulas
iVerify's findings indicate that all flaws (sandbox escape, privilege escalation, remote code execution) exploited in this exploit chain are known or documented, and Apple has already addressed them in the latest iOS releases.
The DarkSword exploit kit uses six vulnerabilities tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
## DarkSword attacks
In a report today, Google Threat Intelligence Group (GTIG) says that DarkSword has been used since at least November 2025 by several threat actors, who deployed three separate malware families:
GHOSTBLADE, a dataminer in JavaScript that steals a swath of information, including crypto wallet data, syst
Mandiant
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
blogs_mandiant·2026-03-18
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
DarkSword supports iOS vers
Wiz
CVE-2025-43520 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43520 [HIGH] CVE-2025-43520 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43520 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 50.7
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk a
https://support.apple.com/en-us/125632https://support.apple.com/en-us/125633https://support.apple.com/en-us/125634https://support.apple.com/en-us/125635https://support.apple.com/en-us/125636https://support.apple.com/en-us/125637https://support.apple.com/en-us/125638https://support.apple.com/en-us/125639https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43520
2025-12-12
Published
2026-03-20
Added to CISA KEV
Exploited in the wild