TROYANOSYVIRUS
Volver a CVEs

CVE-2025-43226

MEDIUM
4.0

Descripcion

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.

Detalles CVE

Puntuacion CVSS v3.14.0
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado7/30/2025
Ultima modificacion4/2/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

apple:ipadosapple:iphone_osapple:macosapple:tvosapple:visionosapple:watchos

Debilidades (CWE)

CWE-125

Referencias

https://support.apple.com/en-us/124147(product-security@apple.com)
https://support.apple.com/en-us/124148(product-security@apple.com)
https://support.apple.com/en-us/124149(product-security@apple.com)
https://support.apple.com/en-us/124150(product-security@apple.com)
https://support.apple.com/en-us/124153(product-security@apple.com)
https://support.apple.com/en-us/124154(product-security@apple.com)
https://support.apple.com/en-us/124155(product-security@apple.com)
http://seclists.org/fulldisclosure/2025/Jul/30(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/31(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/32(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/33(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/35(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/36(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2025/Jul/37(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.