CVE-2025-43280

The issue was resolved by not loading remote images This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.
References
Link Resource
https://support.apple.com/en-us/124147 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

16 Oct 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 4.7
CWE CWE-940

16 Oct 2025, 17:35

Type Values Removed Values Added
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/124147 - () https://support.apple.com/en-us/124147 - Release Notes, Vendor Advisory
CWE NVD-CWE-noinfo
First Time Apple
Apple ipados
Apple iphone Os

16 Oct 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

15 Oct 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-15 20:15

Updated : 2025-10-16 21:15


NVD link : CVE-2025-43280

Mitre link : CVE-2025-43280

CVE.ORG link : CVE-2025-43280


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
CWE
NVD-CWE-noinfo CWE-940

Improper Verification of Source of a Communication Channel