ZDI-25-304: Apple macOS JPEG Image Decoding Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-31251.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-304?
The severity of ZDI-25-304 is rated at 8.8 on the CVSS scale.
How do I fix ZDI-25-304?
To mitigate ZDI-25-304, ensure your macOS is updated to the latest version provided by Apple.
What kind of attack does ZDI-25-304 allow?
ZDI-25-304 allows for remote code execution by attackers who can exploit the vulnerability through malicious pages or files.
Is user interaction required to exploit ZDI-25-304?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
Which versions of macOS are affected by ZDI-25-304?
The vulnerability ZDI-25-304 affects all supported versions of Apple macOS.