CVE-2025-43386 is an out-of-bounds access vulnerability (CWE-125) affecting Apple's iOS, iPadOS, macOS, tvOS, and visionOS, triggered by processing a maliciously crafted media file. Rated High (CVSS 7.8), successful exploitation could lead to unexpected app termination or corrupt process memory. While it requires user interaction, the attack complexity is low, posing a significant risk if exploited. There is currently no evidence of active exploitation, public exploit code, or significant community discussion. Apple has addressed this issue with improved bounds checking in iOS 18.7.2/26.1, iPadOS 18.7.2/26.1, macOS Tahoe 26.1, tvOS 26.1, and visionOS 26.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 26.1CPE matchmatch criteria | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.