Skip to content
COOEY

EXPOSURES › CVE-2025-43200

CVE-2025-43200

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-06-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-43200 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Apple iOS, iPadOS, macOS, watchOS, and visionOS contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

Apple's iOS, iPadOS, macOS, watchOS, and visionOS are affected by an unspecified vulnerability that allows remote code execution when processing maliciously crafted photos or videos shared via iCloud Links. This has been actively exploited in the wild. DIB orgs should expect unauthorized access and potential data exfiltration.

Shame score — Active exploitation in the wild indicates a severe and ongoing risk to the DIB.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.