CVE-2025-43355
BaseFortify
Publication date: 2025-09-15
Last updated on: 2026-04-02
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | ipados | to 18.7 (exc) |
| apple | iphone_os | to 18.7 (exc) |
| apple | macos | From 14.0 (inc) to 14.8 (exc) |
| apple | macos | From 15.0 (inc) to 15.7 (exc) |
| apple | tvos | to 26.0 (exc) |
| apple | visionos | to 26.0 (exc) |
| apple | watchos | to 26.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-843 | The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a type confusion issue that was addressed by improving memory handling. It could allow an app to cause a denial-of-service condition on affected Apple operating systems.
How can this vulnerability impact me? :
An app exploiting this vulnerability may be able to cause a denial-of-service, potentially disrupting the normal operation of your device.
What immediate steps should I take to mitigate this vulnerability?
Update affected Apple operating systems to the fixed versions: tvOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, iOS 18.7, iPadOS 18.7, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26, and iPadOS 26 to address the type confusion issue and prevent potential denial-of-service caused by an app.