CVE-2025-43520Medium· 5.5▾ Midnight⚠ Exploited in the wildPoC availableA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 30.3 · likelihood 0.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the CISA ADP record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Federal remediation due Apr 3, 2026
Last analysed / modified upstream
0.4%
Added to the CISA catalog on Mar 20, 2026. Federal remediation due Apr 3, 2026. View catalog ↗
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
ios_and_ipados < 18.7.2ios_and_ipados < 26.1macOS < 14.8.2macOS < 15.7.2macOS < 26.1tvOS < 26.1visionOS < 26.1watchOS < 26.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84624Medium· 5.5A permissions issue was addressed with improved path validation
CVE-2026-84628Medium· 5.5An authorization issue was addressed with improved state management
CVE-2026-84625Critical· 9.1A permissions issue was addressed with additional sandbox restrictions
CVE-2026-84623High· 7.5An authorization issue was addressed with improved state management
CVE-2026-84621Medium· 5.5An authorization issue was addressed with improved access control
CVE-2026-84616Medium· 5.5A type confusion issue was addressed with improved memory handling