CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2025-43505

    Last Modified: 2 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43397

    Last Modified: 27 Apr 2026

    A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to cause a denial-of-service.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43378

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43401

    Last Modified: 27 Apr 2026

    A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A remote attacker may be able to cause a denial-of-service.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43479

    Last Modified: 22 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43496

    Last Modified: 28 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43438

    Last Modified: 14 Aug 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 4 Nov 2025
    8.1
    High

    CVE-2025-43480

    Last Modified: 22 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43382

    Last Modified: 27 Apr 2026

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    6.2
    Medium

    CVE-2025-43414

    Last Modified: 22 Apr 2026

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43443

    Last Modified: 22 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43455

    Last Modified: 27 Apr 2026

    A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. A malicious app may be able to take a screenshot of sensitive information in embedded views.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43394

    Last Modified: 27 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access protected user data.

    Published: 4 Nov 2025
    4.6
    Medium

    CVE-2025-43422

    Last Modified: 22 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43434

    Last Modified: 22 Apr 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43361

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A malicious app may be able to read kernel memory.

    Published: 4 Nov 2025
    4.4
    Medium

    CVE-2025-43336

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app with root privileges may be able to access private information.

    Published: 4 Nov 2025
    4.6
    Medium

    CVE-2025-43459

    Last Modified: 22 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in watchOS 26.1. An attacker with physical access to a locked Apple Watch may be able to view Live Voicemail.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43377

    Last Modified: 29 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to cause a denial-of-service.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43398

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43376

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43399

    Last Modified: 27 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43458

    Last Modified: 22 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43360

    Last Modified: 27 Apr 2026

    The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-43419

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43462

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43435

    Last Modified: 27 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    2
    Low

    CVE-2025-43423

    Last Modified: 22 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlocked device paired with a Mac may be able to view sensitive user information in system logging.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43474

    Last Modified: 22 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to cause unexpected system termination or read kernel memory.

    Published: 4 Nov 2025
    3.3
    Low

    CVE-2025-43395

    Last Modified: 22 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access protected user data.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43454

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-43507

    Last Modified: 27 Apr 2026

    A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.

    Published: 4 Nov 2025
    3.3
    Low

    CVE-2025-43442

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what other apps a user has installed.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43383

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    5.2
    Medium

    CVE-2025-43481

    Last Modified: 22 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43439

    Last Modified: 27 Apr 2026

    A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to fingerprint the user.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43478

    Last Modified: 27 Apr 2026

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to cause unexpected system termination.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-43424

    Last Modified: 22 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. A malicious HID device may cause an unexpected process crash.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43432

    Last Modified: 22 Apr 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43449

    Last Modified: 27 Apr 2026

    The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to track users between installs.

    Published: 4 Nov 2025
    2.4
    Low

    CVE-2025-43408

    Last Modified: 27 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An attacker with physical access may be able to access contacts from the lock screen.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43469

    Last Modified: 22 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43384

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    6.3
    Medium

    CVE-2025-43412

    Last Modified: 22 Apr 2026

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43500

    Last Modified: 22 Apr 2026

    A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43445

    Last Modified: 22 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43392

    Last Modified: 2 Apr 2026

    The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43405

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    4.6
    Medium

    CVE-2025-43452

    Last Modified: 28 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-43444

    Last Modified: 22 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.

    Published: 4 Nov 2025