cbcvebase.
CVE-2025-43532
published 2025-12-12

CVE-2025-43532: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS…

PriorityP271low2.8CVSS 3.1
AVLACLPRLUIRSUCNINAL
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.27%
18.1th percentile
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.

Affected

17 ranges
VendorProductVersion rangeFixed in
appleios_18.7.3_and_ipados
appleios_26.2_and_ipados
appleios_and_ipados< 18.7.318.7.3
appleios_and_ipados< 26.226.2
applemacos< 15.7.315.7.3
applemacos< 26.226.2
applemacos< 14.8.314.8.3
applemacos>= 15.0 < 15.7.315.7.3
applemacos_sequoia
applemacos_sonoma
applemacos_tahoe
appletvos< 26.226.2
appletvos
applevisionos< 26.226.2
applevisionos
applewatchos< 26.226.2
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-43532 affects the Foundation framework component across Apple platforms; monitor for unexpected app termination triggered by processing malicious data via Foundation APIs
  • The vulnerability is a memory corruption issue in the Foundation component; detection should focus on anomalous memory access patterns or crashes originating from Foundation framework processing untrusted data
  • ·Affected component is Foundation, present across all major Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, watchOS); patched versions vary per platform — ensure all are updated
  • ·No public proof-of-concept or exploit details are available in the provided sources; the attack vector (malicious data) is unspecified beyond triggering Foundation's data-processing code paths

CVSS provenance

nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
vulncheck2.8LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.