PT-2025-31294 · Apple · Visionos+9
Gary Kwong
·
Published
2025-07-29
·
Updated
2025-07-30
·
CVE-2025-43209
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apple Safari (affected versions not specified)
watchOS versions prior to 11.6
iOS versions prior to 18.6
iPadOS versions prior to 18.6
iPadOS version 17.7.9
tvOS versions prior to 18.6
macOS Sequoia versions prior to 15.6
macOS Sonoma versions prior to 14.7.7
visionOS versions prior to 2.6
macOS Ventura versions prior to 13.7.7
Description
An out-of-bounds access issue exists due to insufficient bounds checking when processing maliciously crafted web content. This may lead to an unexpected Safari crash.
Recommendations
Update watchOS to version 11.6 or later.
Update iOS to version 18.6 or later.
Update iPadOS to version 18.6 or later.
Update iPadOS to version 17.7.9.
Update tvOS to version 18.6 or later.
Update macOS Sequoia to version 15.6 or later.
Update macOS Sonoma to version 14.7.7 or later.
Update visionOS to version 2.6 or later.
Update macOS Ventura to version 13.7.7 or later.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Safari
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura
Tvos
Visionos
Watchos