seclists.org
http://seclists.org/fulldisclosure/2025/Jul/30 CVE-2025-43226
MEDIUM
Record summary
CVE-2025-43226 has a selected CVSS score of 4.0 (medium).
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 30, 2025 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 18.6 | affected |
iPadOSBrowse Apple / iPadOS | CVE List | Before 17.7.9 | affected |
macOSBrowse Apple / macOS | CVE List | Before 14.7.7 | affected |
| Before 15.6 | affected | ||
| CVE List | Before 18.6 | affected | |
visionOSBrowse Apple / visionOS | CVE List | Before 2.6 | affected |
watchOSBrowse Apple / watchOS | CVE List | Before 11.6 | affected |
References
Showing 12 of 15seclists.org
http://seclists.org/fulldisclosure/2025/Jul/31 seclists.org
http://seclists.org/fulldisclosure/2025/Jul/32 seclists.org
http://seclists.org/fulldisclosure/2025/Jul/33 seclists.org
http://seclists.org/fulldisclosure/2025/Jul/35 seclists.org
http://seclists.org/fulldisclosure/2025/Jul/36 seclists.org
http://seclists.org/fulldisclosure/2025/Jul/37 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-43226 support.apple.com
https://support.apple.com/en-us/124147 support.apple.com
https://support.apple.com/en-us/124148 support.apple.com
https://support.apple.com/en-us/124149 support.apple.com
https://support.apple.com/en-us/124150