
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43494 is a mail header parsing vulnerability in Apple's Mail application that allows a remote attacker to cause a persistent denial-of-service condition. The flaw was discovered by Taavi Eomäe of Zone Media (zone.ee) and disclosed by Apple on November 5, 2025, with the CVE record published to NVD on December 12, 2025. Affected platforms include iOS prior to 18.7.2, iPadOS prior to 18.7.2, macOS Sonoma prior to 14.8.2, macOS Sequoia prior to 15.7.2, macOS Tahoe prior to 26.1, iOS/iPadOS 26.x prior to 26.1, visionOS prior to 26.1, and watchOS prior to 26.1. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (Apple Advisory iOS 18.7.2, Apple Advisory iOS 26.1).
The root cause is improper input validation (CWE-20) in the mail header parsing logic of Apple's Mail application. An attacker can exploit this by sending a specially crafted email with a malformed mail header to a target device; when the Mail app processes this message, it triggers a persistent denial-of-service condition. The attack vector is network-based, requires no authentication or user interaction, and no special privileges are needed, making it exploitable by any remote sender who can deliver email to a target. Apple addressed the issue with improved input validation checks in the mail header parser (Apple Advisory iOS 18.7.2, Apple Advisory macOS Sequoia 15.7.2).
Successful exploitation results in a persistent denial-of-service affecting the Apple Mail application on the target device. The "persistent" nature of the DoS implies the condition may survive app restarts or require manual remediation (such as deleting the offending message), potentially rendering the Mail app unusable until the problematic email is removed. There is no reported impact on confidentiality or integrity — the vulnerability is limited to availability. The broad scope of affected platforms (iPhone, iPad, Mac, Apple Watch, Apple Vision Pro) means a large population of Apple device users could be targeted (Apple Advisory iOS 26.1, Apple Advisory macOS Tahoe 26.1).
MobileMail on iOS/iPadOS or Mail on macOS) visible in system crash logs or Console.app.~/Library/Logs/DiagnosticReports/ or /Library/Logs/DiagnosticReports/ with repeated entries tied to mail header parsing.Apple has released patches across all affected platforms. Users should update to iOS 18.7.2, iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, iOS 26.1, iPadOS 26.1, visionOS 26.1, or watchOS 26.1 to remediate the vulnerability. As a temporary workaround prior to patching, users experiencing persistent Mail crashes may access their mailbox via webmail or a third-party email client to identify and delete the offending message. No configuration-based mitigation has been published by Apple (Apple Advisory iOS 18.7.2, Apple Advisory macOS Sequoia 15.7.2, Apple Advisory macOS Tahoe 26.1).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."