Applied Cybernetics Group
Threat intel → detection pipeline
Monday, October 5, 2026
Data as of 09:42 UTC

Apple Multiple Products Unspecified Vulnerability

Added to KEV
2025-06-16
Federal due date
2025-07-07
Vendor
Apple
Product
Multiple Products
EPSS
66.9th percentile (score 0.012, as of 2026-10-04)
NVD CVSS v3.1
4.2 (MEDIUM)
Ransomware use
Unknown
ATT&CK
T1005 , T1105 , T1203 · signal rollup
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2025-43200

CISA short description

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

NVD description

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.