CVE-2025-43532
published 2025-12-12CVE-2025-43532: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS…
PriorityP271low2.8CVSS 3.1
AVLACLPRLUIRSUCNINAL
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.27%
18.1th percentile
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.3_and_ipados | — | — |
| apple | ios_26.2_and_ipados | — | — |
| apple | ios_and_ipados | < 18.7.3 | 18.7.3 |
| apple | ios_and_ipados | < 26.2 | 26.2 |
| apple | macos | < 15.7.3 | 15.7.3 |
| apple | macos | < 26.2 | 26.2 |
| apple | macos | < 14.8.3 | 14.8.3 |
| apple | macos | >= 15.0 < 15.7.3 | 15.7.3 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| apple | tvos | < 26.2 | 26.2 |
| apple | tvos | — | — |
| apple | visionos | < 26.2 | 26.2 |
| apple | visionos | — | — |
| apple | watchos | < 26.2 | 26.2 |
| apple | watchos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-43532 affects the Foundation framework component across Apple platforms; monitor for unexpected app termination triggered by processing malicious data via Foundation APIs ↗
- →The vulnerability is a memory corruption issue in the Foundation component; detection should focus on anomalous memory access patterns or crashes originating from Foundation framework processing untrusted data ↗
- ·Affected component is Foundation, present across all major Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, watchOS); patched versions vary per platform — ensure all are updated ↗
- ·No public proof-of-concept or exploit details are available in the provided sources; the attack vector (malicious data) is unspecified beyond triggering Foundation's data-processing code paths ↗
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
vulncheck2.8LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43532: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: macOS Sequoia 15.7.3
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: macOS Sequoia 15.7.3
Apple Security Update: About the security content of macOS Sequoia 15.7.3
Product: macOS Sequoia
Version: 15.7.3
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: watchOS 26.2
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: watchOS 26.2
Apple Security Update: About the security content of watchOS 26.2
Product: watchOS
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: macOS Sonoma 14.8.3
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: visionOS 26.2
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: visionOS 26.2
Apple Security Update: About the security content of visionOS 26.2
Product: visionOS
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: tvOS 26.2
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: tvOS 26.2
Apple Security Update: About the security content of tvOS 26.2
Product: tvOS
Version: 26.2
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
Apple
CVE-2025-43532: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 2.8
CVE-2025-43532 [LOW] CVE-2025-43532: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2025-43532
Component: Foundation
Impact: Processing malicious data may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved bounds checking.
GHSA
GHSA-9q9m-rgvw-p592: A memory corruption issue was addressed with improved bounds checking
ghsa_unreviewed·2025-12-12
CVE-2025-43532 [LOW] CWE-120 GHSA-9q9m-rgvw-p592: A memory corruption issue was addressed with improved bounds checking
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.8.3, macOS Sequoia 15.7.3. Processing malicious data may lead to unexpected app termination.
VulnCheck
Apple macos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
vulncheck·2025·CVSS 2.8
CVE-2025-43532 [LOW] Apple macos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Apple macos Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.
Affected: Apple macos
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://media.jamf.com/documents/white-papers/security-360-mac-2026.pdf
No detection rules found.
No public exploits indexed.
https://support.apple.com/en-us/125884https://support.apple.com/en-us/125885https://support.apple.com/en-us/125886https://support.apple.com/en-us/125887https://support.apple.com/en-us/125888https://support.apple.com/en-us/125889https://support.apple.com/en-us/125890https://support.apple.com/en-us/125891
2025-12-12
Published
Exploited in the wild