CVE-2025-43210

MEDIUM EPSS 28.9%
Published Apr 2, 20262mo ago · Modified Jun 17, 20261w ago
6.3 CVSS 3.1
Medium
Find Similar
Published Apr 2, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

CVSS Details

Base Score
6.3
Exploitability
2.8
Impact
3.4
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Low
Integrity Low
Availability Low

Threat Intelligence

EPSS Exploit Probability
28.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-125 Out-of-bounds Read Memory Safety
CWE-787 Out-of-bounds Write Memory Safety

Affected Products 9

VendorProductVersionRange
appleipados* <17.7.9
appleipados*≥18.0  –  <18.6
appleiphone_os* <18.6
applemacos*≥13.0  –  <13.7.7
applemacos*≥14.0  –  <14.7.7
applemacos*≥15.0  –  <15.6
appletvos* <18.6
applevisionos* <2.6
applewatchos* <11.6

References 8

  • support.apple.com https://support.apple.com/en-us/124147
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124148
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124149
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124150
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124151
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124153
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124154
    Release NotesVendor Advisory
  • support.apple.com https://support.apple.com/en-us/124155
    Release NotesVendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.