CVE-2025-43515: Apple Compressor
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a Compressor server may be able to execute arbitrary code.
Affected products
- Apple Compressor: before 4.11.1 (fixed in 4.11.1)
Published 2025-11-13. Last modified 2026-06-17.