CVE-2025-43385

7.5

Apple · iOS, iPadOS, macOS, tvOS, visionOS

An out-of-bounds access vulnerability in Apple media processing may lead to unexpected application termination or corruption of process memory.

Executive summary

A critical memory safety vulnerability exists across multiple Apple operating systems that could allow an attacker to trigger process crashes or memory corruption via a malicious media file.

Vulnerability

The vulnerability is an out-of-bounds access flaw triggered during the processing of maliciously crafted media files. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:R), this issue is remotely exploitable and does not require authentication, though it necessitates user interaction to initiate the processing of the malicious file.

Business impact

The potential for process memory corruption and application termination poses a risk to system stability and data integrity. While the CVSS score of 7.5 indicates a high risk, the primary impact involves service disruption or potential exploitation of memory states, which could be leveraged for further system compromise. Organizations relying on these devices for sensitive operations face increased exposure to denial-of-service scenarios.

Remediation

Immediate Action: Update all affected Apple devices to the specified patched versions (iOS/iPadOS 18.7.2 or 26.1, macOS 15.7.2 or 26.1, tvOS 26.1, and visionOS 26.1) immediately.

Proactive Monitoring: Monitor system logs for frequent, unexplained application crashes or unexpected service restarts, which may indicate attempted exploitation.

Compensating Controls: Ensure that mobile device management (MDM) policies restrict the automatic opening of untrusted media files and maintain up-to-date endpoint security software.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the broad impact across Apple's ecosystem, administrators should prioritize the deployment of these security updates. The risk of application termination and memory corruption necessitates a proactive patch management cycle to ensure the continued stability and security of the corporate environment.

More Apple CVEs

Sources