Apple Multiple Products Improper Locking Vulnerability

cve CVE-2025-43510 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Apple Multiple Products Improper Locking Vulnerability Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://sup… the claim

What it is to other things

affectsapple/ipados
NVD
affectsapple/iphone_os
NVD
affectsapple/macos
NVD
affectsapple/tvos
NVD
affectsapple/visionos
NVD
affectsapple/watchos
NVD
made_byapple
NVD

In words only, so not counted until a person confirms one:

affectsapple/ios_and_ipados
NVD says “Apple · iOS and iPadOS”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "cisaActionDue": "2026-04-03",
    "cisaExploitAdd": "2026-03-20",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "819E8F86-A336-49A2-853F-249459279A59",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4173F942-2CF6-447E-A942-948F6EF6CE77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7B98B4A6-EFB0-4651-BF56-06917E7CEC85",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "E29A276A-7091-42B2-B893-6A5801A0716E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9827CBDC-8C03-46BA-B534-8533F0975804",
                "versionEndExcluding": "14.8.2",
                "versionStartIncluding": "14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4BE8199E-63D1-496C-B107-52853CFC2311",
                "versionEndExcluding": "15.7.2",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "551159EE-8311-4A13-802D-85871DAB5E77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "290E0D29-CB5B-45A7-9FE3-FD2030B1D1A4",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD3616-65CA-4E5C-849C-3C20ACBCB610",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F9D7F76-13FB-407C-94E5-221B93021568",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes."
      },
      {
        "lang": "es",
        "value": "Una corrupción de memoria se abordó con una comprobación mejorada del estado de bloqueo. Este problema está solucionado en watchOS 26.1, iOS 18.7.2 y iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 y iPadOS 26.1. Una aplicación maliciosa puede causar cambios inesperados en la memoria compartida entre procesos."
      }
    ],
    "id": "CVE-2025-43510",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43510",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-21T04:01:04.069314Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:55.843",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125632"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125633"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125634"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125635"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125636"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125637"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125638"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125639"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Technical Description"
        ],
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43510"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-667"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-667
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-667
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-04-03
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-04-03
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Product
product
not compared
CISA Known Exploited VulnerabilitiesMultiple Products
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Multiple Products
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—
Product
product
not compared
NVDiOS and iPadOS
receipt
Source
NVD
Its words
iOS and iPadOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "cisaActionDue": "2026-04-03",
    "cisaExploitAdd": "2026-03-20",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "819E8F86-A336-49A2-853F-249459279A59",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4173F942-2CF6-447E-A942-948F6EF6CE77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7B98B4A6-EFB0-4651-BF56-06917E7CEC85",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "E29A276A-7091-42B2-B893-6A5801A0716E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9827CBDC-8C03-46BA-B534-8533F0975804",
                "versionEndExcluding": "14.8.2",
                "versionStartIncluding": "14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4BE8199E-63D1-496C-B107-52853CFC2311",
                "versionEndExcluding": "15.7.2",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "551159EE-8311-4A13-802D-85871DAB5E77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "290E0D29-CB5B-45A7-9FE3-FD2030B1D1A4",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD3616-65CA-4E5C-849C-3C20ACBCB610",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F9D7F76-13FB-407C-94E5-221B93021568",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes."
      },
      {
        "lang": "es",
        "value": "Una corrupción de memoria se abordó con una comprobación mejorada del estado de bloqueo. Este problema está solucionado en watchOS 26.1, iOS 18.7.2 y iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 y iPadOS 26.1. Una aplicación maliciosa puede causar cambios inesperados en la memoria compartida entre procesos."
      }
    ],
    "id": "CVE-2025-43510",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43510",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-21T04:01:04.069314Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:55.843",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125632"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125633"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125634"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125635"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125636"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125637"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125638"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125639"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Technical Description"
        ],
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43510"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-667"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "cisaActionDue": "2026-04-03",
    "cisaExploitAdd": "2026-03-20",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "819E8F86-A336-49A2-853F-249459279A59",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4173F942-2CF6-447E-A942-948F6EF6CE77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7B98B4A6-EFB0-4651-BF56-06917E7CEC85",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "E29A276A-7091-42B2-B893-6A5801A0716E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9827CBDC-8C03-46BA-B534-8533F0975804",
                "versionEndExcluding": "14.8.2",
                "versionStartIncluding": "14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4BE8199E-63D1-496C-B107-52853CFC2311",
                "versionEndExcluding": "15.7.2",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "551159EE-8311-4A13-802D-85871DAB5E77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "290E0D29-CB5B-45A7-9FE3-FD2030B1D1A4",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD3616-65CA-4E5C-849C-3C20ACBCB610",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F9D7F76-13FB-407C-94E5-221B93021568",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes."
      },
      {
        "lang": "es",
        "value": "Una corrupción de memoria se abordó con una comprobación mejorada del estado de bloqueo. Este problema está solucionado en watchOS 26.1, iOS 18.7.2 y iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 y iPadOS 26.1. Una aplicación maliciosa puede causar cambios inesperados en la memoria compartida entre procesos."
      }
    ],
    "id": "CVE-2025-43510",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43510",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-21T04:01:04.069314Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:55.843",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125632"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125633"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125634"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125635"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125636"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125637"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125638"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125639"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Technical Description"
        ],
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43510"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-667"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "cisaActionDue": "2026-04-03",
    "cisaExploitAdd": "2026-03-20",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "819E8F86-A336-49A2-853F-249459279A59",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4173F942-2CF6-447E-A942-948F6EF6CE77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7B98B4A6-EFB0-4651-BF56-06917E7CEC85",
                "versionEndExcluding": "18.7.2",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "E29A276A-7091-42B2-B893-6A5801A0716E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9827CBDC-8C03-46BA-B534-8533F0975804",
                "versionEndExcluding": "14.8.2",
                "versionStartIncluding": "14.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4BE8199E-63D1-496C-B107-52853CFC2311",
                "versionEndExcluding": "15.7.2",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "551159EE-8311-4A13-802D-85871DAB5E77",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "290E0D29-CB5B-45A7-9FE3-FD2030B1D1A4",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7DFD3616-65CA-4E5C-849C-3C20ACBCB610",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9F9D7F76-13FB-407C-94E5-221B93021568",
                "versionEndExcluding": "26.1",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes."
      },
      {
        "lang": "es",
        "value": "Una corrupción de memoria se abordó con una comprobación mejorada del estado de bloqueo. Este problema está solucionado en watchOS 26.1, iOS 18.7.2 y iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, tvOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 y iPadOS 26.1. Una aplicación maliciosa puede causar cambios inesperados en la memoria compartida entre procesos."
      }
    ],
    "id": "CVE-2025-43510",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43510",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-21T04:01:04.069314Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:55.843",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125632"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125633"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125634"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125635"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125636"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125637"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125638"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125639"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "Technical Description"
        ],
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43510"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-667"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesApple
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Apple
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-43510",
  "cwes": "CWE-667",
  "dateAdded": "2026-03-20",
  "dueDate": "2026-04-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.apple.com/en-us/125632 ; https://support.apple.com/en-us/125633 ; https://support.apple.com/en-us/125634 ; https://support.apple.com/en-us/125635 ; https://support.apple.com/en-us/125636 ; https://support.apple.com/en-us/125637 ; https://support.apple.com/en-us/125638 ; https://support.apple.com/en-us/125639 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43510",
  "product": "Multiple Products",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.",
  "vendorProject": "Apple",
  "vulnerabilityName": "Apple Multiple Products Improper Locking Vulnerability"
}
—

vulnerability

Apple Multiple Products Improper Locking Vulnerability
zetlyn/cve-kev · 2026-03-20
cwes CWE-667 due_date 2026-04-03 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Multiple Products vendor_project Apple
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
zetlyn/cve-nvd · 2025-12-12
cvss 7.8 product iOS and iPadOS status Analyzed vendor Apple source