ZDI-CAN-26603: ZDI-25-304: Apple macOS JPEG Image Decoding Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-31251.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26603?
The severity of ZDI-CAN-26603 is rated 8.8, indicating a high-risk vulnerability.
How do I fix ZDI-CAN-26603?
To fix ZDI-CAN-26603, ensure that your Apple macOS is updated to the latest version provided by Apple.
What type of attack does ZDI-CAN-26603 involve?
ZDI-CAN-26603 allows remote attackers to execute arbitrary code through user interaction, such as visiting a malicious page or opening a malicious file.
Is user interaction required for ZDI-CAN-26603 to be exploited?
Yes, user interaction is required for the exploitation of ZDI-CAN-26603.
What should I do if my system is affected by ZDI-CAN-26603?
If your system is affected by ZDI-CAN-26603, apply the latest security updates from Apple immediately.