CVE-2025-43200Medium· 4.2▾ Midnight⚠ Exploited in the wild0dayThis issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 23.1 · likelihood 0.2 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jul 7, 2025
Last analysed / modified upstream
1.1%
Added to the CISA catalog on Jun 16, 2025. Federal remediation due Jul 7, 2025. View catalog ↗
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
ipados < 15.8.4ipados >= 16.0, < 16.7.11ipados >= 17.0, < 17.7.5ipados >= 18.0, < 18.3.1iphone_os < 15.8.4iphone_os >= 16.0, <= 16.7.11iphone_os >= 17.0, <= 18.3.1macos >= 13.0, < 13.7.4macos >= 14.0, < 14.7.4macos >= 15.0, < 15.3.1visionos < 2.3.1watchos < 11.3.1Upgrade past the affected range:
ipados 18.3.1iphone_os 15.8.4macos 15.3.1visionos 2.3.1watchos 11.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84624Medium· 5.5A permissions issue was addressed with improved path validation
CVE-2026-65349Medium· 6.6An out-of-bounds read was addressed with improved input validation
CVE-2026-84632High· 7.3The issue was addressed with improved memory handling
CVE-2026-84560Medium· 6.1An authorization issue was addressed with improved state management
CVE-2026-65353Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-64779Low· 3.1A memory corruption vulnerability was addressed with improved locking