2025年8月21日星期四

Apple Products Remote Code Execution Vulnerability

Apple Products Remote Code Execution Vulnerability

Release Date: 21 Aug 2025

RISK: High Risk

TYPE: Operating Systems - Mobile & Apps

A vulnerability has been identified in Apple Products. A remote attacker could exploit this vulnerability to trigger remote code execution and denial of service condition on the targeted system.

 

Note:

CVE-2025-43300 may have been exploited in an extremely sophisticated attack against specific targeted individuals. This vulnerability is caused by an out-of-bounds write weakness discovered by Apple security researchers in the Image I/O framework, which enables applications to read and write most image file formats. Hence the risk level is rated to High Risk.


Impact

  • Remote Code Execution
  • Denial of Service

System / Technologies affected

  • Versions prior to iPadOS 17.7.10
  • Versions prior to iOS 18.6.2 and iPadOS 18.6.2
  • Versions prior to macOS Sequoia 15.6.1
  • Versions prior to macOS Sonoma 14.7.8
  • Versions prior to macOS Ventura 13.7.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • iPadOS 17.7.10  
  • iOS 18.6.2 and iPadOS 18.6.2  
  • macOS Sequoia 15.6.1  
  • macOS Sonoma 14.7.8  
  • macOS Ventura 13.7.8  

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

蘋果產品遠端執行程式碼漏洞

蘋果產品遠端執行程式碼漏洞 發佈日期: 2025年08月21日 風險: 高度風險 類型: 操作系統 - 流動裝置及操作系統 於蘋果產品發現一個漏...