cbcvebase.
CVE-2025-43520
published 2025-12-12

CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…

PriorityP180medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-04-03
Exploited in the wild
EPSS
0.41%
33.0th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

Affected

23 ranges
VendorProductVersion rangeFixed in
appleios_18.7.2_and_ipados
appleios_26.1_and_ipados
appleios_and_ipados< 18.7.218.7.2
appleios_and_ipados< 26.126.1
appleipados< 18.7.218.7.2
appleipados
appleiphone_os< 18.7.218.7.2
appleiphone_os
applemacos< 14.8.214.8.2
applemacos< 15.7.215.7.2
applemacos< 26.126.1
applemacos
applemacos>= 14.0 < 14.8.214.8.2
applemacos>= 15.0 < 15.7.215.7.2
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
appletvos< 26.126.1
appletvos
applevisionos< 26.126.1
applevisionos
applewatchos< 26.126.1
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

otherDarkSword iOS exploit kit
  • CVE-2025-43520 is exploited as part of the DarkSword iOS exploit kit in watering-hole attacks; monitor for iPhone users visiting compromised websites (e-commerce, industrial equipment, local services) particularly Ukrainian-hosted domains.
  • DarkSword wipes temporary files and exits after data theft; forensic artefacts may be minimal — focus on short-lived process execution and rapid file deletion patterns on iOS devices.
  • Threat actors UNC6748 (linked to Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage) are attributed DarkSword operators; use these cluster identifiers for threat-intel pivoting.
  • CVE-2025-43520 affects the Kernel component; prioritise patching to iOS 18.7.2/iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, and other listed OS versions to close the kernel memory-write primitive.
  • CISA KEV deadline is April 3, 2026 for FCEB agencies; treat unpatched Apple devices running affected OS versions as high-priority exposure in asset inventories.
  • ·CVE-2025-43520 is one of six vulnerabilities chained in the DarkSword exploit kit; patching this CVE alone does not fully neutralise the kit — all six flaws (including CVE-2025-31277 and CVE-2025-43510) must be addressed.

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vulncheck5.5MEDIUM
cisa5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.