VulnerabilityModified
CVE-2025-43226
An out-of-bounds read was addressed with improved input validation.
MEDIUM 4.0EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.
- CVSS 3.1
- 4.0 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/124147Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124148Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124149Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124150Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124153Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124154Release Notes, Vendor Advisory
- https://support.apple.com/en-us/124155Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Jul/30
- http://seclists.org/fulldisclosure/2025/Jul/31
- http://seclists.org/fulldisclosure/2025/Jul/32
- http://seclists.org/fulldisclosure/2025/Jul/33
- http://seclists.org/fulldisclosure/2025/Jul/35
- http://seclists.org/fulldisclosure/2025/Jul/36
- http://seclists.org/fulldisclosure/2025/Jul/37
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.