CVE-2025-43385 is an out-of-bounds access vulnerability impacting Apple's iOS, iPadOS, macOS, tvOS, and visionOS operating systems. This medium-severity flaw (CVSS 4.3) requires user interaction, where processing a maliciously crafted media file could lead to unexpected application termination or memory corruption. While the attack vector is network-based with low complexity, there is no known active exploitation, public exploit code, or significant community discussion. Apple has released patches for this issue in iOS/iPadOS 18.7.2 and 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, and visionOS 26.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 15.7.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.