Back to Labs
Security Advisory

CVE-2025-43300

About

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Weakness (CWE):CWE-787

Rainforest analyst review

This is an out-of-bounds write in Apple's image-processing code, in the RawCamera component that handles certain raw image formats. Parsing a maliciously crafted image file miscomputes bounds and writes past the end of an allocated buffer, corrupting memory in a way that an attacker structures to gain control of execution. Because image handling is so deeply integrated into iOS, iPadOS, and macOS, the malicious file can be delivered and processed through ordinary channels, and the flaw needs no interaction beyond the target's device rendering the image.

Apple states it was exploited in an extremely sophisticated attack against specific targeted individuals, the hallmark language of mercenary spyware operations that chain zero-click flaws to compromise phones of journalists, dissidents, and officials. That context matters for prioritization: while the immediate victims are a narrow, high-risk set, once details are public the technique gets studied and can be repurposed. Update to the fixed builds across the iOS 15.8.5, 16.7.12, 17.7.10, and 18.6.2 lines and the corresponding macOS releases immediately, prioritizing high-risk users, and for anyone in a plausible targeting profile, consider Lockdown Mode as an additional layer against this class of image-parsing attack.

References

Related CVEs

Frequently asked questions

What is CVE-2025-43300?

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption.

How severe is CVE-2025-43300?

CVE-2025-43300 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2025-43300 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2025-43300?

Public advisories list the following as affected: ipados, iphone os, macos. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2025-43300?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email