CVE-2025-43515

8.8

Apple · Compressor

A vulnerability in Apple Compressor allows an unauthenticated attacker on the same network to execute arbitrary code by exploiting default external connection handling.

Executive summary

A critical remote code execution vulnerability in Apple Compressor allows unauthenticated network-adjacent attackers to compromise the host system.

Vulnerability

The flaw stems from improper handling of external connections, which previously allowed unauthorized network access. An unauthenticated attacker on the same local network can leverage this to achieve remote code execution.

Business impact

This vulnerability carries a CVSS score of 8.8, indicating a high level of severity due to the potential for full system compromise. Successful exploitation could lead to unauthorized data exfiltration, complete loss of system integrity, and significant operational downtime for organizations relying on Compressor for media processing.

Remediation

Immediate Action: Update Apple Compressor to version 4.11.1 or later immediately to implement the fix that refuses external connections by default.

Proactive Monitoring: Monitor network traffic for unusual connection attempts targeting the Compressor service and review system logs for signs of unauthorized process execution.

Compensating Controls: Restrict network access to the Compressor server to trusted internal segments only, effectively isolating the application from potentially untrusted or guest networks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high impact of remote code execution, organizations must prioritize the update to Compressor 4.11.1 across all affected deployments. Failure to patch leaves systems vulnerable to attackers positioned on the same network, making timely remediation essential for maintaining a secure environment.

More Apple CVEs

Sources