CVE-2025-43224: Apple iPadOS

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

Affected products

  • Apple iPadOS: before 18.6 (fixed in 18.6)
  • Apple iPhone OS: before 18.6 (fixed in 18.6)
  • Apple macOS: before 15.6 (fixed in 15.6)
  • Apple tvOS: before 18.6 (fixed in 18.6)
  • Apple visionOS: before 2.6 (fixed in 2.6)

Published 2025-07-30. Last modified 2026-06-17.