CVE-2025-43300

9.5 CISA KEV

Apple · iOS, iPadOS, and macOS

A critical out-of-bounds write vulnerability in Apple iOS, iPadOS, and macOS allows memory corruption via malicious image processing, facilitating potential remote code execution.

Executive summary

This critical out-of-bounds write vulnerability in Apple operating systems is confirmed to be actively exploited in the wild, posing an immediate risk of system compromise.

Vulnerability

The flaw is an out-of-bounds write vulnerability triggered during the processing of a malicious image file, which results in memory corruption. The vulnerability is exploitable by an unauthenticated attacker.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve memory corruption, which can lead to arbitrary code execution on the target device. Given the CVSS score of 9.5, this represents a critical risk to organizational data confidentiality, integrity, and availability. Compromise of mobile and desktop endpoints could facilitate unauthorized access to sensitive corporate resources and internal communications.

Remediation

Immediate Action: Update all affected Apple devices to the latest versions: iOS and iPadOS 15.8.5, 16.7.12, 17.7.10, 18.6.2, or macOS 13.7.8, 14.7.8, 15.6.1, as appropriate for the specific OS version.

Proactive Monitoring: Monitor device logs for signs of unexpected application crashes or anomalous background processes that may indicate attempts to trigger memory corruption.

Compensating Controls: Ensure that users avoid opening untrusted or unsolicited image files from unknown sources, and maintain device security configurations that limit execution privileges where possible.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub repositories.

Analyst recommendation

The active exploitation of this vulnerability in the wild makes it a top-tier priority for security and IT teams. Organizations must initiate an immediate patching cycle across all fleet devices to mitigate the risk of remote code execution. Failure to apply these updates leaves systems vulnerable to advanced exploitation attempts that bypass standard security controls.

More Apple CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Look Back published
  23. Analyst report written
  24. Fix documented version 15.8.5 per CVE record

Sources