ZDI-25-299: Apple macOS acv2 Codec Converter Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2025-31208.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-299?
ZDI-25-299 has been assigned a CVSS rating indicating a moderate severity due to the requirement of user interaction for exploitation.
How do I fix ZDI-25-299?
To fix ZDI-25-299, ensure that you have the latest updates installed for Apple macOS that address this vulnerability.
What type of information can be disclosed by exploiting ZDI-25-299?
Exploiting ZDI-25-299 can lead to the disclosure of sensitive information stored on affected Apple macOS installations.
Is user interaction required to exploit ZDI-25-299?
Yes, user interaction is required, as the target must visit a malicious webpage or open a malicious file for the exploit to succeed.
Which systems are affected by ZDI-25-299?
ZDI-25-299 affects installations of Apple macOS that have not resolved the identified vulnerability.