Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since August 21, 2025.

CVE-2025-43300

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple · iOS, iPadOS, and macOS

Added to KEV August 21, 2025

Alert details

Source feed
CISA KEV
CVE ID
CVE-2025-43300
CWE
CWE-787
Affected products
iOS, iPadOS, and macOS · Apple iOS, iPadOS, and macOS · Apple

What happened

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

What it means for your business

Apple iOS, iPadOS, and macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43300). Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CISA remediation due date: 2025-09-11. If you need help checking exposure, call (864) 335-9223.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA due date: September 11, 2025

Sources

Related briefs

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.