CVE-2025-43300
KEVCRITICAL 10.0EPSS 22.0%
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 21.99% chance of exploitation in the next 30 days, 97th percentile
- CISA KEV
- added 2025-08-21
- Published
- 2025-08-21
- Updated
- 2026-04-02
Proof-of-concept exploits (9)
- b1n4r1b01/n-days530★ · 2025-09-28
- DarkNavySecurity/PoC226★ · 2025-08-27
- PwnToday/CVE-2025-433006★ · 2025-09-09
- hunters-sec/CVE-2025-43300116★ · 2025-08-24
- veniversum/cve-2025-433000★ · 2025-09-18
- Dark-life944/CVE-2025
- ticofookfook/CVE-2025-43300
- BUSHIGAN/PS4-POC
- IsMyPhonePwned/mimic4★ · 2026-02-05