PT-2025-34177 · Apple · Ipados +5
Published
2025-08-20
·
Updated
2025-08-26
·
CVE-2025-43300
10
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Apple iOS, iPadOS, and macOS versions prior to 18.6.2, 17.7.10, Sonoma 14.7.8, Ventura 13.7.8, and Sequoia 15.6.1.
**Description:**
This vulnerability (CVE-2025-43300) is an out-of-bounds write issue within the ImageIO framework, a core component responsible for processing image files across Apple platforms. Processing a maliciously crafted image file can lead to memory corruption, potentially allowing an attacker to execute arbitrary code. Reports indicate this vulnerability has been actively exploited in targeted attacks, with some reports suggesting high-value individuals, including those in finance and with cryptocurrency holdings, have been specifically targeted. The exploit is considered a “zero-click” vulnerability, meaning it can be triggered without any user interaction, such as simply receiving or previewing a malicious image. The vulnerability allows for remote code execution and potential data theft.
**Recommendations:**
Update all affected Apple devices to the latest available versions: iOS 18.6.2, iPadOS 18.6.2 or 17.7.10, macOS Sonoma 14.7.8, Ventura 13.7.8, and Sequoia 15.6.1.
Exploit
Fix
RCE
Memory Corruption
Weakness Enumeration
Related Identifiers
Affected Products
References · 402
- 🔥 https://github.com/b1n4r1b01/n-days/blob/main/CVE-2025-43300.md⭐ 337 🔗 54 · Exploit
- https://support.apple.com/en-us/124927 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/124928 · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43300 · Security Note
- https://support.apple.com/en-us/124929 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/124925 · Security Note, Vendor Advisory
- https://support.apple.com/en-us/124926 · Security Note, Vendor Advisory
- https://bdu.fstec.ru/vul/2025-10189 · Security Note
- https://twitter.com/ApplSec/status/1958227772050133371 · Twitter Post
- https://twitter.com/BreachNet/status/1959151870716387553 · Twitter Post
- https://twitter.com/NewsNucleus/status/1958361971734299106 · Twitter Post
- https://twitter.com/grok/status/1959268187536777489 · Twitter Post
- https://twitter.com/AmericaGrooves/status/1959878082367521003 · Twitter Post
- https://twitter.com/tenmostsecure/status/1959500186729799856 · Twitter Post
- https://twitter.com/Tigr_B/status/1959239677421953402 · Twitter Post