Home

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.

PUBLISHED Reserved 2025-04-16 | Published 2025-07-29 | Updated 2026-04-02 | Assigner apple

Problem types

Processing a maliciously crafted image may result in disclosure of process memory

Product status

Any version before 18.6
affected

Any version before 17.7.9
affected

Any version before 14.7.7
affected

Any version before 15.6
affected

Any version before 18.6
affected

Any version before 2.6
affected

Any version before 11.6
affected

References

seclists.org/fulldisclosure/2025/Jul/37

seclists.org/fulldisclosure/2025/Jul/36

seclists.org/fulldisclosure/2025/Jul/35

seclists.org/fulldisclosure/2025/Jul/33

seclists.org/fulldisclosure/2025/Jul/32

seclists.org/fulldisclosure/2025/Jul/31

seclists.org/fulldisclosure/2025/Jul/30

support.apple.com/en-us/124147

support.apple.com/en-us/124148

support.apple.com/en-us/124149

support.apple.com/en-us/124150

support.apple.com/en-us/124153

support.apple.com/en-us/124154

support.apple.com/en-us/124155

cve.org (CVE-2025-43226)

nvd.nist.gov (CVE-2025-43226)

Download JSON