PT-2025-31294 · Apple · Visionos+9

Gary Kwong

·

Published

2025-07-29

·

Updated

2025-07-30

·

CVE-2025-43209

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple Safari (affected versions not specified) watchOS versions prior to 11.6 iOS versions prior to 18.6 iPadOS versions prior to 18.6 iPadOS version 17.7.9 tvOS versions prior to 18.6 macOS Sequoia versions prior to 15.6 macOS Sonoma versions prior to 14.7.7 visionOS versions prior to 2.6 macOS Ventura versions prior to 13.7.7
Description An out-of-bounds access issue exists due to insufficient bounds checking when processing maliciously crafted web content. This may lead to an unexpected Safari crash.
Recommendations Update watchOS to version 11.6 or later. Update iOS to version 18.6 or later. Update iPadOS to version 18.6 or later. Update iPadOS to version 17.7.9. Update tvOS to version 18.6 or later. Update macOS Sequoia to version 15.6 or later. Update macOS Sonoma to version 14.7.7 or later. Update visionOS to version 2.6 or later. Update macOS Ventura to version 13.7.7 or later.

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-43209
ZDI-25-673

Affected Products

Apple Macos
Safari
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura
Tvos
Visionos
Watchos