LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-43520: Apple Multiple Products Classic Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-43520 to its Known Exploited Vulnerabilities catalog on Mar 20, 2026, with a federal patch deadline of Apr 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel…

This vulnerability is a classic buffer overflow present in multiple Apple operating systems. A malicious application could exploit it to force unexpected system termination or perform writes to kernel memory.

How it works

The weakness is identified as CWE-120. In this class of flaw, an application fails to properly validate the size of data written into a fixed-length buffer.

Am I affected? How to find it in your systems

The vulnerability affects Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS. Begin by inventorying all managed and unmanaged devices running these operating systems, including mobile, desktop, and embedded deployments.

How to remediate

Apply the vendor-supplied update referenced in the official Apple advisory. This is the primary and most effective action.

If you can't patch immediately

Apply mitigations according to the vendor instructions. Where cloud services are involved, follow applicable BOD 22-01 guidance. If mitigations cannot be implemented, discontinue use of the affected product.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to data breaches in other incidents. You can run a free exposure scan of your email addresses against known breach data to check for prior compromises.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-120
Added to CISA KEVMar 20, 2026
Federal patch deadlineApr 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities