The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption.

cve CVE-2025-43539 1 source, 1 claim · Watch

NVD writes:
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption. El problema se abordó con comprobaciones de límites mejoradas. Este problema se solucionó en watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. El procesamiento de un archivo puede provocar corrupción de memoria. the claim

What it is to other things

affectsapple/macos
NVD
made_byapple
NVD

In words only, so not counted until a person confirms one:

affectsapple/ios_and_ipados
NVD says “Apple · iOS and iPadOS”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD8.8
receipt
Source
NVD
Its words
8.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8E37DC2A-33E6-480B-8DFE-4F6558F0A895",
                "versionEndExcluding": "14.8.3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3428C860-E02D-4FE9-96F4-58EEAAB8321D",
                "versionEndExcluding": "15.7.3",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption."
      },
      {
        "lang": "es",
        "value": "El problema se abordó con comprobaciones de límites mejoradas. Este problema se solucionó en watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. El procesamiento de un archivo puede provocar corrupción de memoria."
      }
    ],
    "id": "CVE-2025-43539",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43539",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-15T20:30:12.782520Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:57.583",
    "references": [
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125884"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125885"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125886"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125887"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125888"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125889"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125890"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125891"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDiOS and iPadOS
receipt
Source
NVD
Its words
iOS and iPadOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8E37DC2A-33E6-480B-8DFE-4F6558F0A895",
                "versionEndExcluding": "14.8.3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3428C860-E02D-4FE9-96F4-58EEAAB8321D",
                "versionEndExcluding": "15.7.3",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption."
      },
      {
        "lang": "es",
        "value": "El problema se abordó con comprobaciones de límites mejoradas. Este problema se solucionó en watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. El procesamiento de un archivo puede provocar corrupción de memoria."
      }
    ],
    "id": "CVE-2025-43539",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43539",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-15T20:30:12.782520Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:57.583",
    "references": [
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125884"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125885"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125886"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125887"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125888"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125889"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125890"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125891"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8E37DC2A-33E6-480B-8DFE-4F6558F0A895",
                "versionEndExcluding": "14.8.3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3428C860-E02D-4FE9-96F4-58EEAAB8321D",
                "versionEndExcluding": "15.7.3",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption."
      },
      {
        "lang": "es",
        "value": "El problema se abordó con comprobaciones de límites mejoradas. Este problema se solucionó en watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. El procesamiento de un archivo puede provocar corrupción de memoria."
      }
    ],
    "id": "CVE-2025-43539",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43539",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-15T20:30:12.782520Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:57.583",
    "references": [
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125884"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125885"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125886"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125887"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125888"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125889"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125890"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125891"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "18.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "14.8.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "15.7.3",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8E37DC2A-33E6-480B-8DFE-4F6558F0A895",
                "versionEndExcluding": "14.8.3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "3428C860-E02D-4FE9-96F4-58EEAAB8321D",
                "versionEndExcluding": "15.7.3",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption."
      },
      {
        "lang": "es",
        "value": "El problema se abordó con comprobaciones de límites mejoradas. Este problema se solucionó en watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. El procesamiento de un archivo puede provocar corrupción de memoria."
      }
    ],
    "id": "CVE-2025-43539",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-43539",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-15T20:30:12.782520Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-12T21:15:57.583",
    "references": [
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125884"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125885"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125886"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125887"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/125888"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125889"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125890"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/125891"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-787"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption.
zetlyn/cve-nvd · 2025-12-12
cvss 8.8 product iOS and iPadOS status Modified vendor Apple source