Vulnerability record · CVE-2025-43300 · published 21 August 2025
CVE-2025-43300: Apple iOS, iPadOS and macOS out-of-bounds write via malicious image
Apple · Ipados
An out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, and fixes are available across multiple OS branches. The flaw matters because it affects core image handling on widely deployed Apple platforms and has confirmed in-the-wild exploitation.
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, confirmed targeted in-the-wild exploitation, and CISA KEV listing with a near-term remediation deadline make this a top patching priority.
What it is
An out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, and fixes are available across multiple OS branches. The flaw matters because it affects core image handling on widely deployed Apple platforms and has confirmed in-the-wild exploitation.
Impact
Successful exploitation corrupts memory and can lead to code execution or system compromise on the affected device. Given the targeted nature of the reported attacks, an attacker could gain control of the victim's device or data.
Attack surface
The vulnerability is reached by processing a malicious image file, which can be delivered remotely (for example via messaging, email or web content) with no authentication required per the CVSS vector. User interaction is not required by the vector, though in practice the victim must handle or view the crafted image.
Exploitation
Apple states the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the KEV catalog on 2025-08-21 with a remediation due date of 2025-09-11. EPSS gives a 30-day exploitation probability of about 22 percent (97.5th percentile), and a public exploit write-up is referenced.
What to do
- Update to the fixed versions: iOS/iPadOS 15.8.5, 16.7.12, 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, or macOS Ventura 13.7.8.
- Prioritize patching for devices used by at-risk individuals such as executives, journalists and activists, consistent with the targeted exploitation reporting.
- Apply mitigations per vendor instructions and follow CISA BOD 22-01 guidance; discontinue use of unsupported devices if no fix is available.
- Restrict or filter untrusted image files at email and web gateways where feasible as a compensating control until patching completes.
Detection
- Monitor for crashes or memory corruption reports in image-processing components (for example ImageIO) on unpatched Apple devices.
- Hunt for delivery of suspicious image files through email, messaging or web channels to high-value users.
- Track patch compliance against the fixed OS versions and flag devices still on vulnerable builds.
- Review endpoint telemetry for unexpected process behavior following image file handling on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-43300 to the Known Exploited Vulnerabilities catalog on 21 August 2025 as "Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 11 September 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/124925 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/124926 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/124927 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/124928 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/124929 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/125141 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/125142 | Release NotesVendor Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/10 | Mailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/14 | Mailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/52 | Mailing ListThird Party Advisory |
| https://github.com/b1n4r1b01/n-days/blob/main/CVE-2025-43300.md | ExploitThird Party Advisory |
| https://github.com/cisagov/vulnrichment/issues/201 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43300 | US Government Resource |
Track CVE-2025-43300 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-43300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.