CVE-2025-43277

HIGH

macOS Sonoma <14.8 - Memory Corruption

Title source: llm
STIX 2.1

Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.8, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted audio file may lead to memory corruption.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (7)
Apple/iOS and iPadOS < 18.6
apple/macos < 14.8
Apple/macOS < 14.8
Apple/macOS < 15.6
Apple/tvOS < 18.6
Apple/visionOS < 2.6
Apple/watchOS < 11.6
Published Jul 30, 2025
Tracked Since Feb 18, 2026