LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-43510: Apple Multiple Products Improper Locking Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-43510 to its Known Exploited Vulnerabilities catalog on Mar 20, 2026, with a federal patch deadline of Apr 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.

Apple products including watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability. A malicious application could cause unexpected changes in memory shared between processes. This matters because shared memory is a common mechanism for efficient inter-process communication on these platforms; interference can affect stability or allow unintended data access within the affected device.

How it works

The weakness is categorized as CWE-667, improper locking. In this class of flaw, synchronization primitives that protect shared resources are not applied consistently or correctly. An attacker-supplied application running on the same device can therefore reach memory regions that should be protected during concurrent access.

Because the products listed share a common kernel and framework base, the same locking omission can appear across phone, tablet, watch, desktop, headset, and set-top operating systems. The CISA summary states only that a malicious application can cause unexpected changes; no further mechanics are provided.

Am I affected? How to find it in your systems

Inventory all managed and unmanaged devices running watchOS, iOS, iPadOS, macOS, visionOS, or tvOS. On Apple platforms this typically means querying MDM solutions, running system_profiler or systeminformation commands locally, or exporting device lists from Apple Business Manager or Apple School Manager. Check every listed operating system family; the vulnerability description does not limit impact to specific hardware models.

How to remediate

Apply mitigations per the vendor instructions referenced in the CISA advisory. Where the affected software is used as a cloud service, follow applicable BOD 22-01 guidance. If mitigations cannot be obtained, discontinue use of the product.

If you can't patch immediately

Until a vendor update can be deployed, reduce exposure by limiting installation of untrusted applications on affected devices. Segment networks so that compromised mobile or desktop endpoints cannot easily reach sensitive internal resources. Monitor for anomalous inter-process behavior through existing endpoint detection tooling, and consider disabling features that rely heavily on shared memory where operationally feasible. If the products are consumed as cloud services, apply the controls required by BOD 22-01.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-667
Added to CISA KEVMar 20, 2026
Federal patch deadlineApr 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities