CVE-2025-43300 is a critical out-of-bounds write vulnerability (CWE-787) affecting Apple's iOS, iPadOS, and macOS, where processing a malicious image file can lead to memory corruption. Rated 10.0 CVSS Critical, this flaw allows for remote, unauthenticated, and zero-click exploitation, potentially leading to complete compromise of affected systems. Apple has confirmed active exploitation as a zero-day in highly sophisticated attacks targeting specific individuals. Urgent patches have been released across affected operating systems, including backports to older versions, to address this actively exploited issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.8.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.7.12CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.7.10CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 18.0, < 18.6.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.8.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.