CVE-2025-43510Active Exploitation(apple / ipados)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-667

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 11 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • Peaked 9d ago at 4 mentions (2026-03-20); latest day: 1
  • 18 total mentions across 11 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

1 version affected across 6 products

Deep dive

Activity timeline18 mentions / 11d
01234Mentions · 2026-03-18: 1Mentions · 2026-03-20: 4Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1Mentions · 2026-03-23: 3Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-06-28: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-24: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-21: 1Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-06-28: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-23: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 103-1803-2003-2103-2203-2303-2403-2503-2603-2706-2810-08
Signal classification4 categories
Active Exploitation
952.9%
Disclosure
529.4%
Patch
211.8%
Exploit
15.9%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-03-181
Patch1
2026-03-204
Active Exploitation1Disclosure3
2026-03-213
Active Exploitation1Disclosure1Patch1
2026-03-221
Active Exploitation1
2026-03-233
Active Exploitation2Disclosure1
2026-03-241
Exploit1
2026-03-251
Active Exploitation1
2026-03-261
Active Exploitation1
2026-03-271
Active Exploitation1
2026-06-281
Active Exploitation1
Full discourse18 posts
  • YogSotho@YogSoth0
    Active Exploitation

    #DarkSword #iOS #Exploit Chain — Six-Stage Nuclear Exploit Kit Exploit Chain: CVE-2025-31277 → CVE-2026-20700 → CVE-2025-14174 → CVE-2025-43510 → CVE-2025-43520 Target: iOS 18.4 - 18.7 (#Safari/#WebKit) Effect: Full device compromise from one click (watering hole) Privileges: Root / Kernel-level #0days #security #hacking #root #CVE

    Post summary

    A six‑stage exploit kit targeting iOS Safari/WebKit is announced, claiming one‑click full device compromise and root/kernel privileges via a chain of CVEs, implying active exploitation in the wild.

    113611988516.2K
    1.9K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件の脆弱性を追加。Apple社複数製品のCVE-2025-31277、CVE-2025-43510、CVE-2025-43520、Craft CMSのCVE-2025-32432、Laravel LivewireのCVE-2025-54068。 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added five CVEs to its catalog of known exploited vulnerabilities, confirming that these weaknesses have been actively exploited in the wild.

    100531.1K
    7.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/20追加) 🛡️No.1548 CVE-2025-31277 Apple Multiple Products Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / CISA-ADP ・種別:バッファ境界の不適切な制限 (CWE-119) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Apple の複数製品において、悪意ある Web コンテンツの処理によりメモリ破損が発生し得る脆弱性。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・被害者が細工された Web コンテンツを処理すること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・メモリ破損 ・任意コード実行の可能性 ・端末侵害の初期侵入点化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が DarkSword での利用を報告。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-31277 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/124147 🛡️No.1549 CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.8 (CVSS Base) / NVD ・種別:不適切なロック (CWE-667) ・CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、プロセス間で共有されるメモリに予期しない変更を生じさせる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・共有メモリの不正変更 ・プロセス間干渉 ・後続の権限奪取やチェーン攻撃の踏み台化 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(Google Threat Intelligence Group が、DarkSword の GPU サンドボックス脱出段階で使用したと説明。) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43510 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125632 🛡️No.1550 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要⚠️ 7.1 (CVSS Base) / NVD ・種別:境界外書き込み (CWE-787) / NVD、クラシックバッファオーバーフロー (CWE-120) / CISA-ADP ・CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 事前認証されていない攻撃者により、悪意あるアプリを介して、予期しないシステム終了やカーネルメモリ書き込みを引き起こされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・被害端末上で悪意あるアプリを実行させること ・脆弱な Apple 製品を利用していること ✅悪用時影響 ・システム異常終了 ・カーネルメモリ書き込み ・権限昇格や端末掌握の足掛かり ([NVD][6]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:あり(GTIG が DarkSword の最終段階 `pe_main.js` において、脆弱性を悪用し物理/仮想メモリ でread/write primitive を構築すると説明) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-43520 https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/ https://support.apple.com/en-us/125633 🛡️No.1551 CVE-2025-32432 Craft CMS Code Injection Vulnerability =================================== ✅概要 ・深刻度:緊急🔥 10.0 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 事前認証されていない攻撃者により、リモートからコード実行される恐れがあります。Craft CMS において、3.0.0-RC1 以上 3.9.15 未満、4.0.0-RC1 以上 4.14.15 未満、5.0.0-RC1 以上 5.6.17 未満が影響を受けます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Craft CMS が外部公開されていること ・脆弱バージョンが稼働していること ・攻撃者は認証不要、ユーザー操作不要 ✅悪用時影響 ・未認証でのリモートコード実行 ・Web サーバ侵害 ・情報窃取 ・Web 改ざんや追加マルウェア設置 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(Craft CMS は 2025-04-17 に “exploited in the wild” を示唆する証拠を確認したと公表) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432](https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 🛡️No.1552 CVE-2025-54068 Laravel Livewire Code Injection Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.8 (CVSS Base) / NVD ・種別:コード生成の不適切な制御 (CWE-94) / GitHub, Inc. ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Livewire v3.0.0 以上 3.6.4 未満において、特定の component property update の hydration 処理に起因。事前認証されていない攻撃者により、特定条件下でリモートからコード実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Livewire v3 系の脆弱バージョンが公開環境で稼働していること ・対象コンポーネントが特定の方法で mounted / configured されていること ✅悪用時影響 ・未認証でのリモートコマンド実行 ・アプリケーションサーバ侵害 ・情報窃取 ・追加マルウェア設置や横展開 ([NVD][7]) ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報あり ・ITW:あり(ThreatHunter .ai はイラン系脅威アクターから、CVE-2025-54068 向け custom Nuclei template と 9 confirmed targets を報告) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-54068 https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/ https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The bulletin reports multiple CVEs—two Apple buffer overflows and two web‑app injection flaws—providing PoCs, exploits, and confirming active exploitation in the wild, with vendor patch references included.

    030414.0K
    42.8K followersView on X
  • CVERiskPilot@cveriskpilot
    Active Exploitation

    3 Apple CVEs hit the CISA KEV this week — all actively exploited: CVE-2025-31277 (memory corruption) CVE-2025-43510 (DoS) CVE-2025-43520 (buffer overflow) iOS, macOS, watchOS, visionOS affected. Update everything. Today. #Apple #AppSec

    Post summary

    Three Apple CVEs that have been added to the CISA KEV list are confirmed as actively exploited across iOS, macOS, watchOS, and visionOS, but no patches, PoC, or exploit code details are provided.

    00030150
    13 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Exploit

    TRC analysis shows UNC6353 deployed the DarkSword exploit kit to chain iOS vulnerabilities CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520. Attackers escaped sandboxes, escalated privileges, and moved laterally across compromised devices to steal cryptocurrency wallet credentials. #MobileSecurity #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/darksword-ios-exploit-kit-2026-unc6353-crypto-theft

    Post summary

    The post reports that attackers used the DarkSword exploit kit to exercise multiple iOS CVEs, demonstrating active exploitation but without providing specific patch information or a PoC.

    01010240
    1.9K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性5件をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 20) CVE-2025-31277 Apple複数製品におけるバッファオーバーフローの脆弱性 CVE-2025-32432 Craft CMS コードインジェクションの脆弱性 CVE-2025-43510 Apple複数製品における不適切なロックの脆弱性 CVE-2025-43520 Apple複数製品におけるクラシックバッファオーバーフローの脆弱性 CVE-2025-54068 Laravel Livewireのコードインジェクション脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/20/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that five CVEs are recognized as actively exploited, citing them in a catalog update without providing PoC or patches.

    00020256
    4.8K followersView on X
  • Jugger@kkimjaechu25852
    Disclosure

    5/10 Step 5~6 커널 메모리 취약점 CVE-2025-43510 + CVE-2025-43520 → 루트 권한 획득 + PPL/SPTM 완전 우회

    Post summary

    The post announces two kernel memory vulnerabilities (CVE‑2025‑43510 and CVE‑2025‑43520) that allow root privilege escalation and bypass of security mechanisms, but it does not provide exploit code, patches, or evidence of active exploitation.

    10000108
    104 followersView on X
  • Cleus@cleus_ai
    Patch

    Darksword hits six main bugs. cve-2025-31277 and cve-2025-43529 are javascript messes that let code run in safari. cve-2026-20700 skips pointer locks for real control. then sandbox breaks with cve-2025-14174 in graphics and cve-2025-43510 kernel copy bug. final kernel grab via cve-2025-43520 race flaw. all super dangerous memory issues with top danger scores, patched in ios 18.7+ and 26.x. those apple and russian flag pics nail it. update asap.

    Post summary

    Six serious Apple CVEs identified by Darksword are addressed in iOS 18.7+ and 26.x, with a call for users to apply the update immediately.

    00001184
    434 followersView on X
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2025-43510 (CVSS 7.8) - Memory corruption flaw in Apple products. Malicious apps can alter shared process memory. Fixed in iOS/iPadOS 18.7.2 & 26.1, macOS updates. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/pvRKF6HwZQ

    0000026
    144 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    🚨 Alerte CISA : Exploitation Active de la Vulnérabilité Critique Apple CVE-2025-43510 – Correctif Urgent Requis (zoneantimalware) https://t.co/vXZwc61CPC

    Post summary

    CISA alerts that the Apple CVE-2025-43510 vulnerability is being actively exploited in the wild and an urgent patch is required.

    00000167
    84 followersView on X
  • TheCyberGuy@TheCyberGu54662
    Active Exploitation

    The CVEs involved: 1️⃣ RCE: CVE-2025-43529 (JIT bugs) 2️⃣ Sandbox Escape: CVE-2026-20700 (PAC Bypass) 3️⃣ Elevation: CVE-2025-43510 (Kernel bug) This level of "state-grade" tech is now being used by commercial hackers

    Post summary

    Three CVEs—CVE-2025-43529 (RCE via JIT bugs), CVE-2026-20700 (sandbox escape via PAC bypass), and CVE-2025-43510 (kernel bug for privilege elevation)—are reportedly being actively exploited by commercial attackers.

    00000154
  • sea-are-pea@seaarepea
    Active Exploitation

    #ITSecurity Apple overflow problems that are getting expoited even after 3+ months. https://www.cve.org/CVERecord?id=CVE-2025-31277 https://www.cve.org/CVERecord?id=CVE-2025-43510 https://www.cve.org/CVERecord?id=CVE-2025-43520

    Post summary

    Apple is facing overflow vulnerabilities that are actively exploited after more than three months, with no public patches or detailed exploit information disclosed.

    00000101
    65 followersView on X
  • yuzuno_oobaka@yuzuno_oobaka
    Patch

    7💫 ユーザー空間の保護を強化した仕組みなのにwritable領域の穴でバイパスされるとkernel exploitの準備が安定する CVE-2025-43510(kernel Copy-On-Writeバグ,AppleM2ScalerCSCDriverのXPC) iOS 26.1 / 18.7.2でパッチ(2025年11-12月)

    Post summary

    The post notes that CVE‑2025‑43510, a kernel Copy‑On‑Write bug affecting AppleM2ScalerCSCDriver’s XPC, is scheduled for patching on iOS 26.1 / 18.7.2 in November‑December 2025.

    00000207
    22 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    CVE-2025-43510 Apple複数製品における不適切なロックの脆弱性 CVE-2025-43520 Apple複数製品におけるクラシックバッファオーバーフローの脆弱性 CVE-2025-54068 Laravel Livewireのコードインジェクション脆弱性

    Post summary

    The text announces three CVEs—two affecting Apple products and one affecting Laravel Livewire—with brief technical descriptors (lock flaw, buffer overflow, injection) but offers no information on exploitation, patches, or PoCs.

    00000188
    46 followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-43510 #Apple Multiple Products Improper Locking Vulnerability https://www.scyscan.com/cve-2025-43510/apple-multiple-products-improper-locking-vulnerability/

    Post summary

    The post lists CVE‑2025‑43510 as a currently exploited Apple vulnerability, but offers no PoC, exploit code, detailed technical data, or patch information.

    00000126
    59 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ CVE-2025-43510: Vulnerabilidad Crítica de Bloqueo en Productos Apple Análisis técnico de CVE-2025-43510, una vulnerabilidad de alto riesgo en watchOS, iOS y más que permite cambios inesperados en memoria compartida. Impacto, miti https://www.ciberplaneta.org/vulnerabilidades/cve-2025-43510-vulnerabilidad-critica-de-bloqueo-en-productos-apple/ #ciberplaneta #vulnerabilidades #cve_2025_43510 #cve #vulnerabilidad #apple #seguridad #infosec #ciberseguridad

    Post summary

    The post offers a brief technical overview of CVE‑2025‑43510, highlighting its high‑risk nature on Apple devices and shared memory abuse, but does not provide a PoC, exploit code, active usage reports, or patch information.

    00000150
    3 followersView on X
  • CiberPlaneta@CiberPlanetaOrg
    Disclosure

    🛡️ Alerta de Seguridad: Vulnerabilidad de Bloqueo Impropio en Múltiples Productos de Apple (CVE-2025-43510) Vulnerabilidad CWE-667 en watchOS, iOS, iPadOS, macOS, visionOS y tvOS de Apple permite a una aplicación maliciosa causar cambios inesperados en memoria compartida entre procesos, con puntuación CVSS 7.8 (Alta). Aplicar mitigaciones del proveedor según BOD 22-01. https://www.ciberplaneta.org/boletines/75/ #ciberplaneta #bulletin #cybersecurity #cve #apple #multiple_products #ioc #infosec #ciberseguridad

    Post summary

    Alert describes CVE-2025-43510, a CWE‑667 memory‑sharing issue across Apple operating systems with a CVSS score of 7.8, and recommends applying the vendor mitigations per BOD 22‑01.

    00000149
    3 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2025-43510 - Apple - macOS - https://www.redpacketsecurity.com/cve-alert-cve-2025-43510-apple-macos/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-43510 #apple #macos

    Post summary

    The notice announces CVE‑2025‑43510 for macOS, pointing to a link for further information, but provides no technical or exploit details or remediation guidance.

    00000137
    3.6K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleipados26.0--
OSappleiphone_os---
OSappleiphone_os26.0--
OSapplemacos---
OSapplemacos26.0--
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more