Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since August 21, 2025.
CVE-2025-43300
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple · iOS, iPadOS, and macOS
Added to KEV August 21, 2025
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2025-43300
- CWE
- CWE-787
- Affected products
- iOS, iPadOS, and macOS · Apple iOS, iPadOS, and macOS · Apple
What happened
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
What it means for your business
Apple iOS, iPadOS, and macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43300). Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CISA remediation due date: 2025-09-11. If you need help checking exposure, call (864) 335-9223.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA due date: September 11, 2025
Sources
Related briefs
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Out of bounds memory access in V8 in Microsoft Edge vulnerability
Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Linux Kernel Race Condition Vulnerability
Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.