Out-of-bounds write in Apple iOS and iPadOS - CVE-2025-43300
Published: August 20, 2025 / Updated: February 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the ImageIO subsystem. A remote attacker can create a specially crafted image file, trick the victim into opening it, trigger an out-of-bounds write and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
iPadOS
macOS
How to mitigate CVE-2025-43300
iPadOS - addressed in versions 18.6.2 22G100, 15.8.5 19H394, 16.7.12 20H364, 17.7.10
macOS - addressed in versions 13.7.8 22H730, 14.7.8 23H730, 15.6.1 24G90
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Apple iOS 18 and iPadOS 18
- Remote code execution in Apple iPadOS
- Remote code execution in macOS Sequoia
- Remote code execution in macOS Sonoma
- Remote code execution in macOS Ventura
- Remote code execution in Apple iOS 15 and iPadOS 15
- Remote code execution in Apple iOS 16 and iPadOS 16