Description
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.
Published: 2025-12-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Persistent denial‑of‑service via mail header parsing
Action: Immediate Patch
AI Analysis

Impact

A mail header parsing issue was discovered that allows malformed headers to trigger an unhandled state in the mail processing engine, potentially causing the device or application to become unresponsive. The vulnerability can lead to a persistent denial‑of‑service condition, disrupting normal mail operations without necessarily compromising data confidentiality. The weakness corresponds to CWE‑20 (Input Validation).

Affected Systems

Apple operating systems—iOS, iPadOS, macOS, visionOS, and watchOS—are affected. The issue is resolved in iOS 18.7.2, iOS 26.1, iPadOS 18.7.2, iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, and watchOS 26.1. Systems running any earlier build of these OS families are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates high impact; the EPSS score of less than 1% suggests a currently low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no publicly known exploits. Based on the description, the likely attack vector involves delivering a maliciously crafted email that includes malformed headers to the target device’s mail application, which then enters an unrecoverable state and requires a restart. This scenario requires prior network access to the target to inject the problematic email, but the exploit does not rely on network attack surface beyond mail delivery and can be performed by any sender with the ability to target a device on a network or via an open mail relay.

Generated by OpenCVE AI on April 27, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest iOS, iPadOS, macOS, visionOS, or watchOS update that includes the fix (e.g., iOS 18.7.2 or later, iOS 26.1 or later, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1).
  • If an immediate OS update is not available, limit the connection of the device to trusted email services and block delivery of emails with suspicious header patterns through network filtering or email gateway policies.
  • Validate that any third‑party mail clients running on the device perform strict header validation, and monitor system logs for recurring parsing errors that could indicate an attempted exploitation.

Generated by OpenCVE AI on April 27, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Title Mail Header Parsing Bug Causing Persistent Denial of Service

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A mail header parsing issue was addressed with improved checks. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. An attacker may be able to cause a persistent denial-of-service. A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.

Fri, 27 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:26.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:26.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:26.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Mon, 15 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Apple ipad Os
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Tahoe
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios
Apple ipad Os
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Tahoe
Apple visionos
Apple watchos

Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description A mail header parsing issue was addressed with improved checks. This issue is fixed in watchOS 26.1, iOS 18.7.2 and iPadOS 18.7.2, macOS Tahoe 26.1, visionOS 26.1, macOS Sonoma 14.8.2, macOS Sequoia 15.7.2, iOS 26.1 and iPadOS 26.1. An attacker may be able to cause a persistent denial-of-service.
References

Subscriptions

Apple Ios Ipad Os Ipados Iphone Os Macos Macos Sequoia Macos Sonoma Macos Tahoe Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:21:24.617Z

Reserved: 2025-04-16T15:27:21.191Z

Link: CVE-2025-43494

cve-icon Vulnrichment

Updated: 2025-12-15T14:50:56.126Z

cve-icon NVD

Status : Modified

Published: 2025-12-12T21:15:55.390

Modified: 2026-04-02T19:20:53.987

Link: CVE-2025-43494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T22:45:15Z

Weaknesses