Exploited Known exploited (KEV) CVE-2025-43510

One record spanning six operating systems: what Apple multiple products means

Apple Multiple Products Added to KEV Mar 20, 2026 Federal remediation due 2026-04-03

An improper locking flaw affecting watchOS, iOS, iPadOS, macOS, visionOS and tvOS. The catalog names the product as multiple products, a heading under which Apple appears 53 times.

Key facts

  • CVE IDCVE-2025-43510
  • Affected (vendor / product)Apple Multiple Products
  • CWECWE-667
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-03 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • An improper locking flaw affecting watchOS, iOS, iPadOS, macOS, visionOS and tvOS.
  • The catalog names the product as multiple products; Apple appears 53 times under it, second most overall.
  • Added 20 March 2026 with a 3 April deadline, a fourteen-day window, with references split by system.
  • None of the 53 Apple entries carries ransomware confirmation, against 28.5% for Windows.

1A product name that says multiple products

In the previous article the product field named one product line. Here it reads Multiple Products. The description lists six: watchOS, iOS, iPadOS, macOS, visionOS and tvOS.

Times Apple appears under multiple products53second most of any product
Operating systems named in this record6watchOS, iOS, iPadOS, macOS, visionOS, tvOS
Window on this record14 daysadded 20 March 2026, due 3 April

2How this differs from Windows

AspectWindows (172 entries)Apple multiple products (53 entries)
What the product field namesone product lineseveral operating systems grouped together
Reach of a single entrylegible from the fieldonly legible from the description
Ransomware use confirmed49 of 172 (28.5%)0 of 53
Leading weakness typesuse after free, out-of-bounds write, link followingout-of-bounds write, use after free, type confusion
Referencesa single update noticeseparate notices for each system

One entry does not cover a fixed amount of ground. The references on this record list support documents split by system, meaning a single entry corresponds to several updates to verify.

3Why zero ransomware confirmations matters

Across Apple's 53 entries, none carries confirmation of use in ransomware campaigns. Against 28.5% for Windows, that contrast says the purpose behind the attacks differs by product. It does not mean safety: these flaws are in the catalog precisely because exploitation was confirmed. What differs is the shape of that use.

The next article takes up a component that ships inside several browsers.

Why it matters

A product name in the catalog does not describe reach. For multiple-product records, the affected devices in your own estate have to be recounted from the description and references.

FAQ

What exactly does multiple products cover?
On this record the description names six systems: watchOS, iOS, iPadOS, macOS, visionOS and tvOS. The product field alone does not say.
What is improper locking?
Inadequate mutual exclusion when several processes handle the same resource. Here the record says memory shared between processes could change unexpectedly.
Does zero ransomware confirmation mean it is safe?
No. These records exist because exploitation was confirmed. What is absent is confirmation of that particular kind of use.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#Apple#Scope#Vulnerability management
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.