CVE-2025-43254: Apple macOS
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.
Affected products
- Apple macOS: from 13.0, before 13.7.7 (fixed in 13.7.7); from 14.0, before 14.7.7 (fixed in 14.7.7); from 15.0, before 15.6 (fixed in 15.6)
Published 2025-07-30. Last modified 2026-06-17.