Skip to main content

CVE detail

CVE-2025-43300

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

CVSS 10.0 · CriticalBuzz score 79.5KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 79.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.5
Mention score
30.0
39 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
4.5
1 repos · best confidence 0.90
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
39 source links · newest first
  • A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked […]

    newssecurityaffairs.comMay 25, 2026, 10:29 AM
  • Shadow AI embedded in everyday apps, combined with outdated mobile devices and zero-click exploits, is creating a new and largely unseen mobile risk.

    newswww.securityweek.comApr 3, 2026, 11:00 AM
  • CISA warns that threat actors are actively using commercial spyware and RATs to target users of mobile messaging apps WhatsApp and Signal. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of threat actors using commercial spyware and remote access trojans (RATs) to target users of popular instant messaging applications, including WhatsApp and Signal. […]

    newssecurityaffairs.comNov 25, 2025, 10:39 AM
  • Threat actors exploited CVE-2025-21042 to deliver malware via specially crafted images to users in the Middle East.

    newswww.securityweek.comNov 7, 2025, 3:29 PM
  • Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.

    vendorunit42.paloaltonetworks.comNov 7, 2025, 11:00 AM
  • In light of new memory safety features added to Apple’s latest iPhone chips that make entire classes of exploits harder to pull off, the company has revamped its bug bounty program to double or quadruple rewards in various attack categories. The payout for an iOS zero-click system-level remote code execution (RCE) exploit responsibly disclosed to […]

    newswww.csoonline.comOct 10, 2025, 7:27 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. A cyberattack on Collins Aerospace disrupted operations at major European airports CISA warns of malware deployed […]

    newssecurityaffairs.comSep 21, 2025, 3:44 PM
  • Apple has rolled out two new updates to patch a zero-day vulnerability in the ImageIO framework, which may have already been exploited in attacks against specific individuals. The flaw, tracked as CVE-2025-43300, and addressed in iOS 16.7.12 and iPadOS 16.7.12, allows for memory corruption on Apple phones when a malicious file is processed. In a […]

    newswww.csoonline.comSep 17, 2025, 12:12 PM
  • Apple announced it has backported patches for a recently addressed actively exploited vulnerability tracked as CVE-2025-43300. Apple has backported security patches released to address an actively exploited vulnerability tracked as CVE-2025-43300. In August 2025, Apple addressed the actively exploited zero-day CVE-2025-43300 in iOS, iPadOS, and macOS. The vulnerability is zero-day out-of-bounds write issue that resides […]

    newssecurityaffairs.comSep 17, 2025, 5:24 AM
  • Apple has announced major mobile and desktop platform releases and addressed an exploited bug in older platforms.

    newswww.securityweek.comSep 16, 2025, 8:44 AM
  • Reported by Meta and WhatsApp, the vulnerability leads to remote code execution and was likely exploited by a spyware vendor.

    newswww.securityweek.comSep 15, 2025, 8:08 AM
  • Samsung fixed actively exploited zero-daySecurity Affairs

    Samsung fixed the remote code execution flaw CVE-2025-21043 that was exploited in zero-day attacks against Android devices. Samsung addressed the remote code execution vulnerability, tracked as CVE-2025-21043, that was exploited in zero-day attacks against Android users. The vulnerability is an out-of-bounds Write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1. A remote attacker can exploit […]

    newssecurityaffairs.comSep 12, 2025, 11:44 AM
  • 8th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 8th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES A supply chain breach involving Salesloft’s Drift integration to Salesforce exposed sensitive customer data from multiple organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Workiva. The attackers accessed Salesforce CRM systems via […]

    vendorresearch.checkpoint.comSep 8, 2025, 11:05 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added WhatsApp, and TP-link flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: CVE-2020-24363 (CVSS 8.8) is a missing authentication flaw in TP-Link TL-WA855RE […]

    newssecurityaffairs.comSep 3, 2025, 12:09 PM
  • The vulnerability (CVE-2025-55177) was exploited along an iOS/macOS zero-day in suspected spyware attacks.

    newswww.securityweek.comSep 2, 2025, 11:39 AM
  • WhatsApp has patched a vulnerability that was used in conjunction with an Apple vulnerability in zero-click attacks.

    newswww.malwarebytes.comSep 1, 2025, 1:55 PM
  • 1st September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 1st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES American consumer credit reporting agency TransUnion has suffered a data breach that resulted in the exposure of sensitive personal information for over 4.4 million individuals in the United States. The leaked data […]

    vendorresearch.checkpoint.comSep 1, 2025, 11:50 AM
  • WhatsApp warns users targeted by advanced spyware, sending threat notifications to affected individuals from the past 90 days. A new zero-click exploit used to hack WhatsApp users, reported Donncha Ó Cearbhaill, Head of Security Lab at @AmnestyTech. WhatsApp has just sent out a round of threat notifications to individuals they believe were targeted by an […]

    newssecurityaffairs.comAug 29, 2025, 9:53 PM
  • 25th August – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 25th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES US pharmaceutical company Inotiv has experienced a ransomware attack that resulted in the unauthorized access and encryption of certain systems and data. The Qilin ransomware gang claimed responsibility and alleged the theft […]

    vendorresearch.checkpoint.comAug 25, 2025, 11:03 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN apps, with a combined 700 million-plus Google Play downloads, are secretly linked, according to a group of researchers from Arizona State University and Citizen Lab. Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300) Apple has fixed yet another vulnerability (CVE-2025-43300) that has … More →

    newswww.helpnetsecurity.comAug 24, 2025, 8:00 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Kidney dialysis firm DaVita confirms ransomware attack compromised data of 2.7M people China-linked Silk Typhoon APT […]

    newssecurityaffairs.comAug 24, 2025, 7:17 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple iOS, iPadOS, and macOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple iOS, iPadOS, and macOS flaw, tracked as CVE-2025-43300, to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple addressed the actively exploited zero-day CVE-2025-43300 in iOS, iPadOS, and […]

    newssecurityaffairs.comAug 22, 2025, 7:18 AM
  • Apple addressed a vulnerability impacting iOS, iPadOS, and macOS that it is under active exploitation in the wild. Apple addressed an actively exploited zero-day, tracked as CVE-2025-43300, in iOS, iPadOS, and macOS. The vulnerability is zero-day out-of-bounds write issue that resides in the ImageIO framework, an attacker could exploit it to cause memory corruption when processing […]

    newssecurityaffairs.comAug 21, 2025, 4:54 PM
  • Apple has released security updates to patch a zero-day vulnerability tracked as CVE-2025-43300 for all platforms

    newswww.malwarebytes.comAug 21, 2025, 12:04 PM
  • Apple has rolled out iOS and macOS updates that resolve a zero-day vulnerability exploited in highly targeted attacks.

    newswww.securityweek.comAug 21, 2025, 8:51 AM
  • No excerpt available.

    Mitigationwww.cisa.govAug 21, 2025, 1:15 AM
  • No excerpt available.

    Exploitgithub.comAug 21, 2025, 1:15 AM
  • No excerpt available.

    Exploitgithub.comAug 21, 2025, 1:15 AM
  • No excerpt available.

    Exploitseclists.orgAug 21, 2025, 1:15 AM
  • No excerpt available.

    Exploitseclists.orgAug 21, 2025, 1:15 AM
  • No excerpt available.

    Exploitseclists.orgAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/125142support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/125141support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/124929support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/124928support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/124927support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/124926support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • https://support.apple.com/en-us/124925support.apple.com

    No excerpt available.

    Vendor Advisorysupport.apple.comAug 21, 2025, 1:15 AM
  • Apple has fixed yet another vulnerability (CVE-2025-43300) that has apparently been exploited as a zero-day “in an extremely sophisticated attack against specific targeted individuals.” About CVE-2025-43300 CVE-2025-43300 is an out-of-bounds write issue that could be triggered by a vulnerable device processing a malicious image file, leading to exploitable memory corruption. The vulnerability affects the Image I/O framework used by Apple’s iOS and macOS operating systems. Apple has fixed this flaw with improved bounds checking in: … More →

    newswww.helpnetsecurity.comAug 20, 2025, 7:23 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.90 · max 0 stars
  • b1n4r1b01/n-daysHigh confidence
    githubNVD Exploit reference0 starsDiscovered Aug 6, 2026, 12:20 AM

    NVD labels the source link as Exploit; this is not independent verification of the repository's code.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence