Out-of-Bounds Read Vulnerability in macOS by Apple
CVE-2025-43254

7.1HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
30 July 2025

What is CVE-2025-43254?

A vulnerability in macOS products allows for an out-of-bounds read that may result in unexpected termination of applications when processing maliciously crafted files. The issue has been mitigated with enhanced input validation in recent updates, specifically in macOS Sequoia 15.6, Ventura 13.7.7, and Sonoma 14.7.7. This vulnerability poses a risk to users, making it essential to update to the latest versions to ensure protection.

Affected Version(s)

macOS < 15.6

macOS < 14.7

macOS < 13.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.