CVE-2025-43218: Apple macOS
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.
Affected products
- Apple macOS: before 15.6 (fixed in 15.6)
Published 2025-07-30. Last modified 2026-06-17.