CVE-2025-43300: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Other sources
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
— CISA
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.5 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 15.8.5 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 16.7.12 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 18.6.2 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 15.8.5 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 16.7.12 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 18.6.2 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 17.7.10 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.7.8 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.7.8 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.6.1 - Compensating control
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2025-43300?
CVE-2025-43300 is classified as a high-severity vulnerability due to its potential for triggering an out-of-bounds write.
How do I fix CVE-2025-43300?
To mitigate CVE-2025-43300, upgrade to the latest versions of affected products: macOS Sequoia 15.6.1, iOS 18.6.2, iPadOS 18.6.2, macOS Sonoma 14.7.8, or macOS Ventura 13.7.8.
Which versions are vulnerable to CVE-2025-43300?
CVE-2025-43300 affects macOS Sequoia versions prior to 15.6.1, iOS and iPadOS versions prior to 18.6.2, macOS Sonoma versions prior to 14.7.8, and macOS Ventura versions prior to 13.7.8.
What types of software are impacted by CVE-2025-43300?
CVE-2025-43300 impacts Apple products including macOS Sequoia, iOS, iPadOS, macOS Sonoma, and macOS Ventura.
Is there any workaround for CVE-2025-43300?
No specific workarounds are provided for CVE-2025-43300; the best course of action is to apply the latest updates provided by Apple.