CVE-2025-43221

HIGH

macOS Sequoia <15.6 - Memory Corruption

Title source: llm
STIX 2.1

Description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (9)
Apple/iOS and iPadOS < 18.6
apple/ipados < 18.6
apple/iphone_os < 18.6
apple/macos < 15.6
Apple/macOS < 15.6
apple/tvos < 18.6
Apple/tvOS < 18.6
apple/visionos < 2.6
Apple/visionOS < 2.6
Published Jul 30, 2025
Tracked Since Feb 18, 2026