CVE-2025-43223

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.7, iPadOS 17.7.9, iOS 18.6 and iPadOS 18.6, macOS Sonoma 14.7.7, watchOS 11.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. A non-privileged user may be able to modify restricted network settings.
References
Link Resource
https://support.apple.com/en-us/124147 Release Notes Vendor Advisory
https://support.apple.com/en-us/124148 Release Notes Vendor Advisory
https://support.apple.com/en-us/124149 Release Notes Vendor Advisory
https://support.apple.com/en-us/124150 Release Notes Vendor Advisory
https://support.apple.com/en-us/124151 Release Notes Vendor Advisory
https://support.apple.com/en-us/124153 Release Notes Vendor Advisory
https://support.apple.com/en-us/124154 Release Notes Vendor Advisory
https://support.apple.com/en-us/124155 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

31 Jul 2025, 19:58

Type Values Removed Values Added
References () https://support.apple.com/en-us/124147 - () https://support.apple.com/en-us/124147 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124148 - () https://support.apple.com/en-us/124148 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124149 - () https://support.apple.com/en-us/124149 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124150 - () https://support.apple.com/en-us/124150 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124151 - () https://support.apple.com/en-us/124151 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124153 - () https://support.apple.com/en-us/124153 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124154 - () https://support.apple.com/en-us/124154 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/124155 - () https://support.apple.com/en-us/124155 - Release Notes, Vendor Advisory
First Time Apple tvos
Apple visionos
Apple ipados
Apple iphone Os
Apple
Apple macos
Apple watchos
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

30 Jul 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de denegación de servicio mejorando la validación de entrada. Este problema está corregido en macOS Ventura 13.7.7, iPadOS 17.7.9, iOS 18.6 y iPadOS 18.6, macOS Sonoma 14.7.7, watchOS 11.6, macOS Sequoia 15.6, tvOS 18.6 y visionOS 2.6. Un usuario sin privilegios puede modificar la configuración de red restringida.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-20

30 Jul 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-30 00:15

Updated : 2025-07-31 19:58


NVD link : CVE-2025-43223

Mitre link : CVE-2025-43223

CVE.ORG link : CVE-2025-43223


JSON object : View

Products Affected

apple

  • iphone_os
  • macos
  • ipados
  • tvos
  • watchos
  • visionos
CWE
CWE-20

Improper Input Validation