CVE-2025-43510 is a memory corruption vulnerability in Apple's consumer operating systems that allows a malicious application to cause unexpected changes in shared memory. This requires local access and user interaction to install a malicious app, making it unsuitable for direct internet exploitation despite being actively exploited in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2025-12-12
Added to CISA KEV: 2026-03-20 98 DAYS BETWEEN CVE AND KEV
CVE-2025-43510 is a high-severity memory corruption vulnerability affecting Apple operating systems, which has been identified as being actively exploited in the wild [2] [3].
| Affected Platforms | Fixed Version |
|---|---|
| iOS | 18.7.2 |
| iPadOS | 18.7.2 |
| watchOS | 26.1 |
*Note: Additional versions, such as iOS/iPadOS 26.1, have also been noted in security databases as containing the fix [4].*
The vulnerability is a memory corruption flaw that can be triggered by a malicious application to arbitrarily modify the contents of memory shared between processes. The flaw is caused by improper lock state checking, which allows a race condition that results in unintended writes. If exploited, anβ¦
CVE-2025-43510 (CVSS 7.8) is an improper locking vulnerability where a malicious application can cause unexpected changes in memory shared ...
Once initial access is obtained, attackers exploit CVE-2025-43510, a vulnerability caused by improper lock-state validation that enables ...
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, ...
Description. A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, ... An official website of the United States government Here's how you knowβ¦