Remote Image Loading Flaws in Apple Products
CVE-2025-43496

7.5HIGH

Key Information:

Vendor

Apple

Vendor
CVE Published:
4 November 2025

What is CVE-2025-43496?

A vulnerability has been identified that allows remote content to be loaded even when users have disabled the 'Load Remote Images' setting across multiple Apple platforms. This flaw can lead to unintended data exposure and may put users at risk if sensitive content is rendered without user consent. Apple has addressed this issue with enhanced logic in their recent software updates.

Affected Version(s)

iOS and iPadOS < 26.1

macOS < 15.7

visionOS < 26.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43496 : Remote Image Loading Flaws in Apple Products