CVE-2025-43424

Plain English Summary

AI-powered analysis for quick understanding

An attacker can use a malicious human interface device (like a keyboard or mouse) to crash processes on iPads running specific versions of the operating system. This requires the attacker to physically connect their harmful device to the iPad, making it a localized threat.

Technical Description

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.1. A malicious HID device may cause an unexpected process crash.

CVSS Vector Analysis

Attack VectorAdjacent Network
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References