One record spanning six operating systems: what Apple multiple products means
An improper locking flaw affecting watchOS, iOS, iPadOS, macOS, visionOS and tvOS. The catalog names the product as multiple products, a heading under which Apple appears 53 times.
Key facts
- CVE IDCVE-2025-43510
- Affected (vendor / product)Apple Multiple Products
- CWECWE-667
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-04-03 (U.S. federal civilian agencies, BOD 22-01)
Key points
- An improper locking flaw affecting watchOS, iOS, iPadOS, macOS, visionOS and tvOS.
- The catalog names the product as multiple products; Apple appears 53 times under it, second most overall.
- Added 20 March 2026 with a 3 April deadline, a fourteen-day window, with references split by system.
- None of the 53 Apple entries carries ransomware confirmation, against 28.5% for Windows.
1A product name that says multiple products
In the previous article the product field named one product line. Here it reads Multiple Products. The description lists six: watchOS, iOS, iPadOS, macOS, visionOS and tvOS.
2How this differs from Windows
One entry does not cover a fixed amount of ground. The references on this record list support documents split by system, meaning a single entry corresponds to several updates to verify.
3Why zero ransomware confirmations matters
Across Apple's 53 entries, none carries confirmation of use in ransomware campaigns. Against 28.5% for Windows, that contrast says the purpose behind the attacks differs by product. It does not mean safety: these flaws are in the catalog precisely because exploitation was confirmed. What differs is the shape of that use.
The next article takes up a component that ships inside several browsers.
Why it matters
A product name in the catalog does not describe reach. For multiple-product records, the affected devices in your own estate have to be recounted from the description and references.
FAQ
What exactly does multiple products cover?
What is improper locking?
Does zero ransomware confirmation mean it is safe?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- Vendor / reference advisory
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).