An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Is CVE-2025-43300 exploited?
Listed in the CISA KEV catalog on 2025-08-21.
Federal remediation due 2025-09-11.
Past that date by 338 days.
EPSS puts exploitation in the next 30 days at 20%.
Public exploit code: none found in monitored sources.