PT-2025-34177 · Apple · Macos Sonoma+5
Published
2025-08-20
·
Updated
2026-04-17
·
CVE-2025-43300
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions: Apple iOS, iPadOS, and macOS versions 15.6.1, 15.7, 15.8.5, 16.7.12, 17.7.10, and 18.6.2 are affected.
Description: Apple has addressed a zero-day vulnerability (CVE-2025-43300) in the ImageIO framework. This is an out-of-bounds write issue that can be exploited by processing a maliciously crafted image file, potentially leading to remote code execution. The vulnerability has been actively exploited in targeted attacks, with reports suggesting it has been used to compromise devices and steal data, including cryptocurrency wallets. The flaw affects iOS, iPadOS, and macOS. Attackers can exploit this vulnerability without user interaction, simply by sending a malicious image.
Recommendations: Update to the latest versions of iOS, iPadOS, and macOS (15.6.1, 15.7, 15.8.5, 16.7.12, 17.7.10, and 18.6.2) to patch the vulnerability.
Exploit
Fix
DoS
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura