ZDI-25-298: Apple macOS MP4 File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-31233.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-298?
ZDI-25-298 has a CVSS rating of 8.8, indicating a high severity level.
How do I fix ZDI-25-298?
To fix ZDI-25-298, update your Apple macOS to the latest version provided by Apple.
What type of attack is associated with ZDI-25-298?
ZDI-25-298 is associated with remote code execution attacks requiring user interaction.
Are there any specific requirements to exploit ZDI-25-298?
Yes, exploitation of ZDI-25-298 requires the user to visit a malicious web page or open a malicious file.
Which versions of Apple macOS are affected by ZDI-25-298?
ZDI-25-298 affects all vulnerable installations of Apple macOS that have not been updated.