Description
The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.
Published: 2025-10-15
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information exposure via remote image loading in Mail on iOS/iPadOS Lockdown Mode
Action: Apply OS Update
AI Analysis

Impact

Mail can display remote images when forwarding an email while the device is in Lockdown Mode, potentially exposing sensitive information or unintended content to the recipient. The vulnerability stems from the system’s behavior of rendering remote image content without user consent, which could be exploited to harvest data about the device or its user, and in some contexts could lead to malicious code execution via crafted image payloads. The weakness is described as a failure to sanitize or block remote image requests, aligned with CWE‑940.

Affected Systems

Apple iOS and iPadOS devices running versions earlier than 18.6. The issue is fixed in iOS 18.6 and iPadOS 18.6. Mail is the specific application affected, and only the Lockdown Mode context allows the vulnerability to be exercised.

Risk and Exploitability

The CVSS score is 4.7, indicating a medium severity. The EPSS score is below 1 %, suggesting very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no active exploit is reported. Attackers would need to convince a user to forward an email while the device is in Lockdown Mode; consent or local user action is typically required, making exploitation less likely but still possible through social engineering.

Generated by OpenCVE AI on April 27, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 18.6 or iPadOS 18.6 to apply the vendor‑issued fix.
  • Configure Mail to block remote images when downloading or displaying emails, especially in Lockdown Mode.
  • Verify that email forwarding in Lockdown Mode does not embed remote image requests or observe any anomalous external traffic.

Generated by OpenCVE AI on April 27, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 28 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Mail Remote Image Exposure in Lockdown Mode

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was resolved by not loading remote images This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode. The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ios
Apple ipad Os
Vendors & Products Apple ios
Apple ipad Os

Thu, 16 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-940
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Thu, 16 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os

Thu, 16 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Description The issue was resolved by not loading remote images This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:56.959Z

Reserved: 2025-04-16T15:24:37.101Z

Link: CVE-2025-43280

cve-icon Vulnrichment

Updated: 2025-10-16T13:46:14.385Z

cve-icon NVD

Status : Modified

Published: 2025-10-15T20:15:34.893

Modified: 2026-04-02T19:20:19.293

Link: CVE-2025-43280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T23:45:15Z

Weaknesses