CVE-2025-43300General(apple / ipados)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-11. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 56 mentions across 29 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 30 signals
  • Technical details provided in 32 signals
  • General: 18 classified signals
  • Peaked 18d ago at 11 mentions (2026-03-10); latest day: 1
  • 56 total mentions across 29 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline56 mentions / 29d
036811Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-03: 1Mentions · 2026-02-09: 3Mentions · 2026-02-13: 1Mentions · 2026-03-04: 1Mentions · 2026-03-06: 2Mentions · 2026-03-09: 5Mentions · 2026-03-10: 11Mentions · 2026-03-11: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 1Mentions · 2026-03-24: 1Mentions · 2026-03-29: 1Mentions · 2026-04-02: 3Mentions · 2026-04-12: 1Mentions · 2026-04-16: 5Mentions · 2026-04-17: 2Mentions · 2026-04-27: 1Mentions · 2026-05-27: 1Mentions · 2026-07-16: 1Mentions · 2026-08-18: 2Mentions · 2026-08-19: 1Mentions · 2026-08-26: 1Mentions · 2026-09-02: 1Mentions · 2026-09-22: 1Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-09-02: 1Exploit Tool / Code · 2026-04-16: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 4Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-26: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-09: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 5Patch / Workaround · 2026-03-10: 9Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-09-02: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-31: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-13: 1Technical Details · 2026-03-09: 4Technical Details · 2026-03-10: 9Technical Details · 2026-03-24: 1Technical Details · 2026-04-16: 5Technical Details · 2026-04-17: 1Technical Details · 2026-08-18: 2Technical Details · 2026-08-19: 1Technical Details · 2026-08-26: 1Technical Details · 2026-09-02: 101-2801-3002-0302-1303-0603-1003-1503-2404-0204-1604-2707-1608-1909-0209-27
Signal classification5 categories
General
1832.7%
Patch
1527.3%
Active Exploitation
1221.8%
Disclosure
712.7%
PoC
35.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-01-282
Active Exploitation1Disclosure1
2026-01-291
Patch1
2026-01-301
Active Exploitation1
2026-01-311
Active Exploitation1
2026-02-031
Disclosure1
2026-02-093
General1Patch2
2026-02-131
Patch1
2026-03-041
General1
2026-03-062
Active Exploitation1General1
2026-03-095
Active Exploitation1Patch4
2026-03-1011
Active Exploitation3Disclosure2General2Patch4
2026-03-111
General1
2026-03-152
General2
2026-03-161
General1
2026-03-241
Patch1
2026-03-291
General1
2026-04-023
Disclosure1General2
2026-04-121
General1
2026-04-165
Disclosure2General2PoC1
2026-04-172
Active Exploitation1Patch1
2026-04-271
PoC1
2026-05-271
General1
2026-07-161
General1
2026-08-182
Active Exploitation1General1
2026-08-191
Active Exploitation1
2026-08-261
Active Exploitation1
2026-09-021
PoC1
2026-09-221
Patch1
Full discourse20 posts
  • Hermes Tool@Hermes_tooll
    Patch

    Zero-Click iPhone Hack via WhatsApp Images : Quarkslab blog post analyzing the patch for Apple's iOS CVE-2025-42EYHgEzWEdjJgYKAu8VjC4DohVYUMbvZ6Ua45MgSaYBTFv3725expKB69YsjM6Utj99E6Sn3LpcxQ4mNrwfrJLM5NGbWiQthrough apps like WhatsApp) - http://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html https://t.co/gO8F3LAxhe

    Post summary

    The tweet points to a Quarkslab blog post that analyzes the patch for iOS CVE‑2025‑43300, providing mitigation details but no evidence of active exploitation or technical depth.

    18304161.8K1.5K153.3K
    2.3K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    WhatsApp 0-Click Crash ~ CVE-2025-43300 https://t.co/D6MhAZSw3I

    Post summary

    The tweet announces the newly identified WhatsApp 0-Click Crash vulnerability CVE-2025-43300, offering a link for additional information but providing no exploitation or patch details.

    956147234133.1K
    12.1K followersView on X
  • Yahya Focking A.@BukanYahya
    General

    Again wrong, CVE-2025-43300 CVE-2025-55177 Zero fucking click ios

    Post summary

    The statement merely lists two CVE numbers with no additional context or evidence of exploitation, patching, or technical detail.

    1432444013246.5K
    2.8K followersView on X
  • ثامر الغالي@alghali
    Patch

    غياب سطر برمجي واحد سمح باختراق الآيفون (واتساب وإيمسج) بصورة فقط! 🫢💻 ثغرة CVE-2025-43300 الخطيرة من نوع Zero-click؛ لا تحتاج لضغط رابط أو فتح ملف، بمجرد وصول الصورة ومعالجتها في الخلفية لإنشاء "المعاينة" يتم اختراق الجهاز فوراً. السبب؟ خطأ بسيط في التحقق من حدود الذاكرة (OOB Write) أثناء فك ضغط صور الـ DNG. آبل أصلحتها في أغسطس الماضي مع تحديث iOS 18.6.2. هذا هو السطر المنقذ الذي أضافته آبل (الذي يبدأ بـ if) لمنع التجاوز: 😅👇

    Post summary

    The post details the zero‑click CVE‑2025‑43300 vulnerability, its memory‑overflow nature, and notes Apple’s August iOS 18.6.2 patch, emphasizing the availability of a fix rather than attack code.

    815023622538.9K
    85.7K followersView on X
  • Manuel Guerra@CiberPoliES
    Active Exploitation

    ACTUALIZACIÓN ROBO WHATSAPP: Todo apunta, al menos, que una de las campañas que se ha lanzado estos días en España de suplantación de Whatsapp se está ejecutando mediante un ataque zero-click basado en la vulnerabilidad CVE-2025-43300, por un problema de renderizado de imágenes en los iPhone sin actualizar. Para que se entienda: Si tienes un iPhone con iOS 16 (sin actualizar) y te mandan una foto maliciosa por Whatsapp, esta imagen "trucada" hará que un atacante externo pueda tomar el control de tu Whatsapp sin que tu puedas hacer nada, ya que tú sesión se duplicará. Lo notarás ya que tú sesión de Whatsapp quedará inestable con cortes y reconexiones, quizás el móvil se caliente bastante, además, es posible que tus contactos comiencen a recibir mensajes que tu no has mandado y que nunca verás como enviados en tu telefono. La clave es que tampoco verás que hay otro dispositivo vinculado, realmente han secuestrado tu sesión que se estará activando y desactivando en bucle durante el tiempo que dure el ataque (por eso se calienta el móvil) Por lo tanto, la recomendación/obligación es actualizar tu versión de iOS por encima de iOS 16. (iOS 16 se lanzó en 2022, actualmente ya vamos por iOS 26)

    Post summary

    The post warns that WhatsApp on iOS 16 is being hijacked via a zero‑click image rendering exploit (CVE‑2025‑43300) in ongoing Spanish campaigns, urging users to upgrade their OS.

    65851325321.1K
    24.8K followersView on X
  • Soufiane@S0ufi4n3
    General

    The art of patch diffing Zero-Click iPhone Hack via WhatsApp Images : https://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html

    Post summary

    The post references a blog analyzing a zero‑click iPhone exploit (CVE‑2025‑43300) via WhatsApp images, but provides no tangible PoC, exploit code, patch, or technical details.

    0180113807.6K
    14.4K followersView on X
  • Clandestine@akaclandestine
    Disclosure

    Reverse engineering of Apple's iOS 0-click CVE-2025-43300: 2 bytes that make size matter - Quarkslab's blog https://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html

    Post summary

    The blog post discloses technical details of Apple iOS CVE-2025-43300, explaining how a 2‑byte 0‑click flaw operates and providing patch‑analysis, but no PoC or active exploitation is indicated.

    016094566.4K
    56.1K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    iOS 18.6.1, iOS 18.6.2 - iOS 0-click CVE-2025-43300 Reverse engineering of Apple's iOS 0-click CVE-2025-43300: 2 bytes that make size matter The vulnerability seems to be located in the ImageIO.framework. Frameworks and functionalities are implemented https://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html

    Post summary

    The blog outlines a reverse‑engineering analysis of iOS 0‑click CVE‑2025‑43300, identifies the flaw in ImageIO, and discusses patching, but it does not provide exploit code or evidence of active attacks.

    013089519.2K
    3.0K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    Zero-Click iPhone Hack via WhatsApp Images : Quarkslab blog post analyzing the patch for Apple's iOS CVE-2025-42EYHgEzWEdjJgYKAu8VjC4DohVYUMbvZ6Ua45MgSaYBTFv3725expKB69YsjM6Utj99E6Sn3LpcxQ4mNrwfrJLM5NGbWiQthrough apps like WhatsApp) - http://blog.quarkslab.com/patch-analysis-of-Apple-iOS-CVE-2025-43300.html https://t.co/9M046j66LD

    Post summary

    The tweet highlights a Quarkslab blog post that analyzes a patch for Apple's iOS CVE-2025-43300, but offers no PoC, exploit details, or evidence of active exploitation.

    0101391.7K
    3.5K followersView on X
  • Anas@Naz_style
    General

    @khanhduytran0 CVE that might be useful for IOS 18 JB Kernel CVE-2024-54518 CVE-2024-54522 CVE-2024-54523 Sandbox/ Privilege CVE-2024-54468 CVE-2024-54529 CVE-2024-54535 WebKit CVE-2024-54543 CVE-2025-14174 CVE-2025-43529 CVE-2025-43300

    Post summary

    The tweet lists several CVE identifiers that may be useful for an iOS 18 jailbreak, but provides no additional details or actionable information.

    010134902
    75 followersView on X
  • Nana Boakye Trumu 🇬🇭🇺🇸@Khalyfa7_
    Active Exploitation

    The Result: The file exploits a memory bug in the OS (like CVE-2025-43300 on iOS), allowing a remote rootkit or spyware (like a modern Pegasus variant) to install itself. No clicking required. The victim is compromised the moment the notification hits their screen.

    Post summary

    The text announces that a memory bug (similar to CVE‑2025‑43300) is being exploited in real‑world attacks, compromising victims instantly via a malicious notification without user interaction.

    1201128.2K
    8.8K followersView on X
  • Grok@grok
    Active Exploitation

    Analyzed Quarkslab article on CVE-2025-43300: OOB write in ImageIO DNG JPEG lossless decompression (mismatch SamplesPerPixel=2 vs NumComponents=1 causes 2x buffer overflow). Zero-click via WhatsApp images; patched with bounds checks in iOS 18.6.2. Image shows patched call with field checks. Skills: ARM64 RE, binary diffing (BinDiff), disassembly (Binary Ninja/Ghidra), iOS internals (dyld_cache, frameworks), memory corruption, C++/ObjC, technical writing/diagrams. Learning path (scratch): 1. C/Asm basics. 2. Ghidra/IDA intro. 3. Diffing/fuzzing. 4. iOS RE (IPSW tools). 5. Vuln chaining. Free: Ghidra, LiveOverflow YT, "Practical Reverse Engineering" PDF. Paid: IDA Pro ($), Binary Ninja Pro, Udemy RE courses.

    Post summary

    CVE-2025-43300 causes an OOB write in iOS ImageIO DNG decompression, was exploited via WhatsApp images and has been patched in iOS 18.6.2.

    10056696
    8.4M followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    General

    Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300 https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The provided excerpt merely points to a write‑up on CVE-2025‑43300, without indicating any PoC, exploit code, active exploitation, patch, or in‑depth technical details.

    02032964
    40.1K followersView on X
  • Grok@grok
    Active Exploitation

    @ankurpandeyvns @kowalski35438 @thematrixb0t Regarding iPhone security: CVE-2025-43300 is a zero-day flaw in Apple's Image I/O framework, enabling zero-click RCE via crafted images. It affects iOS <18.6.2, iPadOS <18.6.2, macOS <Sequoia 15.6.1, etc. Actively exploited since Aug 2025; Apple patched it. Update your devices.

    Post summary

    CVE-2025-43300 is a zero‑day flaw in Apple’s Image I/O framework that has been actively exploited since August 2025, but Apple has issued a patch; users are advised to update their devices.

    10060360
    8.1M followersView on X
  • Grok@grok
    Active Exploitation

    Yes, it was real. CVE-2025-43300 was an out-of-bounds write in Apple's ImageIO (RawCamera for DNG JPEG-lossless images). Chained with WhatsApp's CVE-2025-55177, attackers could force a malicious image download/processing via WhatsApp with zero clicks, enabling RCE in targeted spyware attacks. Actively exploited pre-patch. Apple fixed it Aug 20 2025 (iOS 18.6.2+); WhatsApp too. Update both now to stay safe.

    Post summary

    CVE‑2025‑43300 is an out‑of‑bounds write in Apple’s ImageIO that was actively exploited via WhatsApp before a patch was released on August 20, 2025; both Apple and WhatsApp have fixed the issue.

    100232.1K
    8.4M followersView on X
  • CWZ | #JavidShah | 🧡 🇳🇱 🇮🇷 🇮🇱 🇺🇸 🧡@Cyberwarzonecom
    Patch

    Apple iOS CVE-2025-43300: Patch Analysis Reveals ImageIO Zero-Click Exploit - https://cyberwarzone.com/2026/03/10/apple-ios-cve-2025-43300-imageio-zero-click/

    Post summary

    Patch analysis for CVE‑2025‑43300 uncovered a zero‑click exploit in Apple iOS’s ImageIO, underscoring the vulnerability’s severity and the importance of applying the available fix.

    01040177
    6.4K followersView on X
  • Grok@grok
    PoC

    ¡Claro! Esta "herramienta" es un **Proof of Concept (PoC)** para **CVE-2025-43300**, una vulnerabilidad 0-click en el framework RawCamera de Apple (usado por WhatsApp para procesar imágenes DNG). El PoC genera un archivo DNG malformado y lo envía automáticamente vía WhatsApp. Al llegar al dispositivo víctima (iOS, macOS o iPadOS), la app procesa la imagen sin que el usuario haga nada y **se cierra inesperadamente** (crash). Es un demo ético de investigación de DarkNavySecurity para mostrar cómo se explotó la vuln antes del parche en macOS 15.6.1. No es un "hacker tool" listo para atacar, sino análisis técnico. Más detalles en su GitHub: https://github.com/DarkNavySecurity/PoC/tree/main/CVE-2025-43300 ¡Interesante vuln en parsing de imágenes!

    Post summary

    Se muestra un PoC que explota un fallo de 0-click en RawCamera de Apple mediante un DNG malformado enviado a través de WhatsApp, provocando un crash antes de la corrección en macOS 15.6.1, con código disponible en GitHub.

    10111842
    8.7M followersView on X
  • VulnTracker@vuln_tracker
    General

    0-click + cross-platform impact? That’s a dangerous combo. CVE-2025-43300 shows how messaging apps remain a high-value attack surface - no user interaction needed is always a red flag. Curious to see patch timelines and real-world exploitation signals on this one. http://vulntracker.io

    Post summary

    The post highlights a 0‑click, cross‑platform messaging app vulnerability but offers no proofs of concept, exploit code, active exploitation evidence, patches, or false‑positive claims.

    00013978
    538 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2023-41993 3 - CVE-2025-64755 4 - CVE-2025-43300 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without offering additional context, such as exploitation details, patches, or technical analyses.

    00031347
    1.7K followersView on X
  • 🔴 ESPACIO@EspacioNoticias

    ESTAFA EN WHATSAPP SUPLANTA CUENTAS Y PIDE DINERO Una vulnerabilidad en iOS y otra en WhatsApp se usaron en cadena para entrar en cuentas y pedir transferencias a los contactos. Los primeros incidentes aparecieron en mayo en Italia; se identificaron los fallos CVE-2025-43300 y CVE-2025-55177. Apple y WhatsApp lanzaron parches en septiembre de 2025 (iOS 16.7.12; WhatsApp 2.25.21.73 y 2.25.21.78). WhatsApp notificó a menos de 200 usuarios afectados. Si recibes pedidos de dinero desde un contacto, verifica por otro medio y mantén iOS y WhatsApp actualizados. Lee la nota completa en el link en bio. 📲 #Tecnología #Ciberseguridad #WhatsApp #Apple

    010205.5K
    3.1M followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more