PT-2025-34177 · Apple · Ipados+5

Published

2025-08-20

·

Updated

2026-03-12

·

CVE-2025-43300

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple iOS, iPadOS, macOS versions prior to 18.6.2, 17.7.10, and macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8.
Description Apple addressed a critical zero-day vulnerability (CVE-2025-43300) in the ImageIO framework. This is an out-of-bounds write issue that allows for remote code execution (RCE) via a crafted image file, requiring no user interaction (zero-click exploit). The vulnerability has been actively exploited in targeted attacks, potentially leading to device hijacking and data theft, including cryptocurrency wallets. The flaw affects iOS, iPadOS, and macOS. Reports indicate the vulnerability was used in sophisticated attacks.
Recommendations Update all affected Apple devices to the latest versions: iOS 18.6.2, iPadOS 18.6.2 or 17.7.10, macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8.

Exploit

Fix

DoS

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-10189
CVE-2025-43300

Affected Products

Apple Macos
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura