PT-2025-34177 · Apple · Macos Sequoia +5

Published

2025-08-20

·

Updated

2025-12-01

·

CVE-2025-43300

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple iOS, iPadOS, macOS versions prior to 18.6.2, 17.7.10, and 15.8.5
Description Apple addressed a critical zero-day vulnerability (CVE-2025-43300) in the ImageIO framework, an out-of-bounds write issue that could lead to remote code execution (RCE) with no user interaction required. This flaw was reportedly exploited in targeted attacks, potentially impacting high-value individuals and cryptocurrency users. The vulnerability allows attackers to execute arbitrary code by processing a maliciously crafted image file. The flaw was actively exploited in the wild, and Apple released emergency updates to address it. The vulnerability affects iOS, iPadOS, and macOS.
Recommendations Update all affected devices to the latest versions: iOS 18.6.2, iPadOS 18.6.2 or 17.7.10, and macOS Sequoia 15.6.1, Sonoma 14.7.8, or Ventura 13.7.8.

Exploit

Fix

DoS

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-10189
CVE-2025-43300

Affected Products

Apple Macos
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura