CVE-2025-43518: Input Validation
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, watchOS 26.2. An app may be able to inappropriately access files through the spellcheck API.
Other sources
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
AppleMobileFileIntegrity. The issue was addressed by adding additional logic.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43539
- CVE-2025-43519
- CVE-2025-46289
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-43513
- CVE-2025-46276
- CVE-2025-43509
- CVE-2025-43538
- CVE-2025-43463
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
- CVE-2025-43320
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-43523
- CVE-2025-43542
- CVE-2025-43527
- CVE-2025-46288
- CVE-2025-46279
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-46277
- CVE-2025-46290
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-46298
- CVE-2025-43511
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-43534
- CVE-2025-46311
- CVE-2025-43475
- CVE-2025-43428
- CVE-2025-46292
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-43501
- CVE-2025-46297
- CVE-2025-46283
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-46278
- CVE-2025-43524
- CVE-2025-46291
- CVE-2025-43410
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-43514
- CVE-2025-46282
Frequently Asked Questions
What is the severity of CVE-2025-43518?
CVE-2025-43518 is a vulnerability related to a logic issue that can allow file access through the spellcheck API.
How do I fix CVE-2025-43518?
To fix CVE-2025-43518, update to the latest versions of macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, or other affected Apple products to ensure the security enhancements are applied.
Which Apple products are affected by CVE-2025-43518?
Affected products include macOS Sonoma, macOS Sequoia, iOS, iPadOS, watchOS, and macOS Tahoe.
What type of vulnerability is CVE-2025-43518?
CVE-2025-43518 is classified as a logic issue that involves improper file access through application programming interfaces.
Is there a workaround for CVE-2025-43518 if I can't update right now?
Currently, the best mitigation for CVE-2025-43518 is to update to the patched versions provided by Apple, as there are no alternative workarounds suggested.