EXPOSURES › CVE-2025-43200
CVE-2025-43200
HIGH ⌖ ON CISA KEV · EXPLOITEDApple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
Apple's iOS, iPadOS, macOS, watchOS, and visionOS are affected by an unspecified vulnerability that allows remote code execution when processing maliciously crafted photos or videos shared via iCloud Links. This has been actively exploited in the wild. DIB orgs should expect unauthorized access and potential data exfiltration.
Shame score — Active exploitation in the wild indicates a severe and ongoing risk to the DIB.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.