CVE-2025-43424
Plain English Summary
AI-powered analysis for quick understanding
An attacker can use a malicious human interface device (like a keyboard or mouse) to crash processes on iPads running specific versions of the operating system. This requires the attacker to physically connect their harmful device to the iPad, making it a localized threat.
Technical Description
The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1. A malicious HID device may cause an unexpected process crash.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Nov 4, 2025
5 months ago
Last Modified
Mar 13, 2026
25 days ago
Vendor
apple
Product
ipados
Related Vulnerabilities
This vulnerability allows an attacker to potentially execute harmful code on a user's device by tricking them into viewing specially crafted web content. It primarily affects users of Safari on specific versions of macOS and iOS, and requires the victim to visit a malicious website for the attack to succeed.
This vulnerability allows an attacker to run their own harmful code on your device by tricking it into processing specially crafted web content. It can be exploited when users visit malicious websites, so keeping your device updated is crucial to protect against potential attacks.
This vulnerability allows an attacker to run any code they want on a device with full system access, which could lead to complete control over the device. It requires the attacker to trick the user into running a malicious app on iPadOS or iOS versions prior to the latest updates.
This vulnerability allows an attacker to run harmful code on a user's device by tricking them into visiting a specially crafted website. It requires the user to open a malicious webpage in Safari, which could compromise their device and data.