PT-2025-34177 · Apple · Macos Sequoia+5
CVE-2025-43300
·
Published
2025-08-20
·
Updated
2026-09-02
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 15.8.5
iOS versions 16.x prior to 16.7.12
iOS versions prior to 18.6.2
iPadOS versions prior to 15.8.5
iPadOS versions 16.x prior to 16.7.12
iPadOS versions 17.x prior to 17.7.10
iPadOS versions prior to 18.6.2
macOS Ventura versions prior to 13.7.8
macOS Sonoma versions prior to 14.7.8
macOS Sequoia versions prior to 15.6.1
Description
An out-of-bounds write issue exists in the ImageIO framework, a core image processing library used across iOS, iPadOS, and macOS. The flaw occurs during the decompression of DNG JPEG lossless images when there is a mismatch between the
SamplesPerPixel and NumComponents variables, leading to a buffer overflow. Processing a specially crafted malicious image file can result in memory corruption, potentially allowing a remote attacker to execute arbitrary code. This is a zero-click issue because the system automatically uses ImageIO to parse image previews, meaning the victim does not need to open the file for the attack to trigger. Apple has received reports that this issue was exploited in extremely sophisticated attacks targeting specific individuals.Recommendations
Update iOS to version 15.8.5, 16.7.12, or 18.6.2.
Update iPadOS to version 15.8.5, 16.7.12, 17.7.10, or 18.6.2.
Update macOS Ventura to version 13.7.8.
Update macOS Sonoma to version 14.7.8.
Update macOS Sequoia to version 15.6.1.
Avoid viewing or processing images from untrusted sources.
Exploit
Fix
RCE
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura