CVE ID
CVE-2025-43300
Vulnerability Name
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
- Project: Apple
- Product: iOS, iPadOS, and macOS
Date
- Date Added: 2025-08-21
- Due Date: 2025-09-11
Description
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.apple.com/en-us/124925 ; https://support.apple.com/en-us/124926 ; https://support.apple.com/en-us/124927 ; https://support.apple.com/en-us/124928 ; https://support.apple.com/en-us/124929 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43300
Related Security News
- Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack
- Apple backports zero-day patches to older iPhones and iPads
- Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms
- Samsung patches actively exploited zero-day reported by WhatsApp
- Apple warns customers targeted in recent spyware attacks
- CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active Exploitation
- WhatsApp Patches Zero-Click Exploit Targeting iOS and macOS Devices
- WhatsApp Issues Emergency Update for Zero-Click Exploit Targeting iOS and macOS Devices
- WhatsApp patches vulnerability exploited in zero-day attacks
Top comments (0)