CVE-2025-43218: Apple macOS

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.

Affected products

  • Apple macOS: before 15.6 (fixed in 15.6)

Published 2025-07-30. Last modified 2026-06-17.