Threat Intelligence / CVE / CVE-2025-43520

CVE-2025-43520

CISA KEV
CVSS 5.5 (MEDIUM) · EPSS 0.3% · Priority 9/10 · Published 2025-12-12

As of 2026-04-03, CVE-2025-43520 is a CVSS 5.5 (MEDIUM-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 0.3%. Threadlinqs Intelligence tracks 1 threat exploiting it.

Last updated: 2026-04-03

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

CWE-120

Exploitation status

CISA KEV-listed (known exploited)

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2025-43520 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.