CVE-2025-43300 Details
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
A vulnerability in the ImageIO component of various Apple operating systems, including macOS Sonoma, macOS Ventura, macOS Sequoia, iOS, and iPadOS, allows for an out-of-bounds write that could be exploited to cause memory corruption. This issue was addressed with improved bounds checking. Apple is aware of reports that this vulnerability may have been exploited in a sophisticated attack targeting specific individuals.
Users can update to macOS Sonoma 14.7.8, macOS Ventura 13.7.8, macOS Sequoia 15.6.1, iOS 18.6.2, or iPadOS 17.7.10 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | Aug 21, 2025 | Sep 11, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple ipados | < 15.8.5 >= 16.0, < 16.7.12 >= 17.0, < 17.7.10 >= 18.0, < 18.6.2 |
CPE
Remediation
| |
| apple iphone os | < 15.8.5 >= 16.0, < 16.7.12 >= 17.0, < 18.6.2 |
CPE
Remediation
| |
| apple macos | >= 13.0, < 13.7.8 >= 14.0, < 14.7.8 >= 15.0, < 15.6.1 |
CPE
Remediation
| |
Change History
23 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Modified Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Nov 26, 2025 | Modified Analysis | [email protected] |
| Nov 26, 2025 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | Modified Analysis | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 4, 2025 | Modified Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Sep 16, 2025 | Modified Analysis | [email protected] |
| Sep 15, 2025 | CVE Modified | [email protected] |
| Aug 26, 2025 | Modified Analysis | [email protected] |
| Aug 26, 2025 | CVE Modified | CVE |
| Aug 22, 2025 | Initial Analysis | [email protected] |
| Aug 22, 2025 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Aug 21, 2025 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | New CVE Received | [email protected] |