CVE-2025-43494
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43494 is a mail header parsing vulnerability in Apple's Mail application that allows a remote attacker to cause a persistent denial-of-service condition. The flaw was discovered by Taavi Eomäe of Zone Media (zone.ee) and disclosed by Apple on November 5, 2025, with the CVE record published to NVD on December 12, 2025. Affected platforms include iOS prior to 18.7.2, iPadOS prior to 18.7.2, macOS Sonoma prior to 14.8.2, macOS Sequoia prior to 15.7.2, macOS Tahoe prior to 26.1, iOS/iPadOS 26.x prior to 26.1, visionOS prior to 26.1, and watchOS prior to 26.1. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (Apple Advisory iOS 18.7.2, Apple Advisory iOS 26.1).

Technical details

The root cause is improper input validation (CWE-20) in the mail header parsing logic of Apple's Mail application. An attacker can exploit this by sending a specially crafted email with a malformed mail header to a target device; when the Mail app processes this message, it triggers a persistent denial-of-service condition. The attack vector is network-based, requires no authentication or user interaction, and no special privileges are needed, making it exploitable by any remote sender who can deliver email to a target. Apple addressed the issue with improved input validation checks in the mail header parser (Apple Advisory iOS 18.7.2, Apple Advisory macOS Sequoia 15.7.2).

Impact

Successful exploitation results in a persistent denial-of-service affecting the Apple Mail application on the target device. The "persistent" nature of the DoS implies the condition may survive app restarts or require manual remediation (such as deleting the offending message), potentially rendering the Mail app unusable until the problematic email is removed. There is no reported impact on confidentiality or integrity — the vulnerability is limited to availability. The broad scope of affected platforms (iPhone, iPad, Mac, Apple Watch, Apple Vision Pro) means a large population of Apple device users could be targeted (Apple Advisory iOS 26.1, Apple Advisory macOS Tahoe 26.1).

Exploitation steps

  1. Craft a malicious email: Construct an email with a specially malformed mail header designed to trigger the parsing flaw in Apple's Mail application. The exact header structure is not publicly documented, but the vulnerability lies in improper validation of header content.
  2. Deliver the email: Send the crafted email to the target's email address. No prior access to the device or user interaction beyond the Mail app processing the message is required.
  3. Trigger persistent DoS: When the Apple Mail app on the target device fetches and attempts to parse the malicious email, the improper input validation causes a persistent denial-of-service condition, rendering the Mail app non-functional.
  4. Persistence: Because the DoS is described as "persistent," the Mail app may continue to fail on subsequent launches until the offending message is removed from the mailbox, potentially requiring the user to access their email via another client or webmail to delete it (Apple Advisory iOS 18.7.2, Apple Advisory iOS 26.1).

Indicators of compromise

  • Logs: Repeated crashes or unexpected terminations of the Mail application process (e.g., MobileMail on iOS/iPadOS or Mail on macOS) visible in system crash logs or Console.app.
  • Application Behavior: Apple Mail persistently fails to launch or crashes immediately upon opening, particularly after receiving a new email from an unknown sender.
  • Network: Inbound email from an unknown or suspicious sender containing unusual or malformed header fields (e.g., excessively long header values, non-standard characters, or malformed structured header syntax).
  • File System (macOS): Crash reports for the Mail process in ~/Library/Logs/DiagnosticReports/ or /Library/Logs/DiagnosticReports/ with repeated entries tied to mail header parsing.

Mitigation and workarounds

Apple has released patches across all affected platforms. Users should update to iOS 18.7.2, iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, iOS 26.1, iPadOS 26.1, visionOS 26.1, or watchOS 26.1 to remediate the vulnerability. As a temporary workaround prior to patching, users experiencing persistent Mail crashes may access their mailbox via webmail or a third-party email client to identify and delete the offending message. No configuration-based mitigation has been published by Apple (Apple Advisory iOS 18.7.2, Apple Advisory macOS Sequoia 15.7.2, Apple Advisory macOS Tahoe 26.1).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management