CVE-2025-43542
published 2025-12-12CVE-2025-43542: This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.85%
54.1th percentile
This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Tahoe 26.2, visionOS 26.2. Password fields may be unintentionally revealed when remotely controlling a device over FaceTime.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.3_and_ipados | — | — |
| apple | ios_26.2_and_ipados | — | — |
| apple | ios_and_ipados | < 18.7.3 | 18.7.3 |
| apple | ios_and_ipados | < 26.2 | 26.2 |
| apple | macos | < 26.2 | 26.2 |
| apple | macos | < 15.7.3 | 15.7.3 |
| apple | macos_sequoia | — | — |
| apple | macos_tahoe | — | — |
| apple | visionos | < 26.2 | 26.2 |
| apple | visionos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor FaceTime remote control sessions for unexpected exposure of password field contents — the vulnerability causes password fields to be unintentionally revealed during remote device control over FaceTime. ↗
- ·The vulnerability is in the FaceTime component and affects iOS 18.7.3/iPadOS 18.7.3 and earlier, macOS Sequoia 15.7.3 and earlier, and their respective successor releases (iOS/iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2). Fixed versions are iOS 18.7.3, iPadOS 18.7.3, iOS 26.2, iPadOS 26.2, macOS Sequoia 15.7.3, macOS Tahoe 26.2, and visionOS 26.2. ↗
- ·Root cause is improper state management in the FaceTime component — the fix involved improved state management to prevent password field disclosure during remote control sessions. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cc4h-r4x5-p77q: This issue was addressed with improved state management
ghsa_unreviewed·2025-12-12
CVE-2025-43542 [HIGH] CWE-200 GHSA-cc4h-r4x5-p77q: This issue was addressed with improved state management
This issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.3. Password fields may be unintentionally revealed when remotely controlling a device over FaceTime.
VulnCheck
Apple iOS/iPadOS/visionOS and macOS Sequoia/Tahoe FaceTime Password Disclosure
vulncheck·2025·CVSS 7.5
CVE-2025-43542 [HIGH] Apple iOS/iPadOS/visionOS and macOS Sequoia/Tahoe FaceTime Password Disclosure
Apple iOS/iPadOS/visionOS and macOS Sequoia/Tahoe FaceTime Password Disclosure
This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Tahoe 26.2, visionOS 26.2. Password fields may be unintentionally revealed when remotely controlling a device over FaceTime.
Affected: Apple macos
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://media.jamf.com/documents/white-papers/security-360-mac-2026.pdf
Apple
CVE-2025-43542: visionOS 26.2
vendor_apple·2025-12-12·CVSS 7.5
CVE-2025-43542 [HIGH] CVE-2025-43542: visionOS 26.2
Apple Security Update: About the security content of visionOS 26.2
Product: visionOS
Version: 26.2
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
Apple
CVE-2025-43542: macOS Sequoia 15.7.3
vendor_apple·2025-12-12·CVSS 7.5
CVE-2025-43542 [HIGH] CVE-2025-43542: macOS Sequoia 15.7.3
Apple Security Update: About the security content of macOS Sequoia 15.7.3
Product: macOS Sequoia
Version: 15.7.3
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
Apple
CVE-2025-43542: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 7.5
CVE-2025-43542 [HIGH] CVE-2025-43542: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
Apple
CVE-2025-43542: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 7.5
CVE-2025-43542 [HIGH] CVE-2025-43542: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
Apple
CVE-2025-43542: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 7.5
CVE-2025-43542 [HIGH] CVE-2025-43542: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2025-43542
Component: FaceTime
Impact: Password fields may be unintentionally revealed when remotely controlling a device over FaceTime
Description: This issue was addressed with improved state management.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-12
Published
Exploited in the wild