
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43219 is a memory corruption vulnerability in Apple's Model I/O framework affecting macOS Sequoia versions prior to 15.6. The flaw involves improper memory handling when processing a maliciously crafted image or USD file, which may corrupt process memory or disclose memory contents. It was discovered by Michael DePlante (@izobashi) of Trend Micro Zero Day Initiative and patched by Apple on July 29, 2025 with the release of macOS Sequoia 15.6. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory, Github Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), rooted in insufficient memory handling within Apple's Model I/O framework when parsing maliciously crafted image or USD files. An attacker can exploit this by delivering a specially crafted file that, when processed by the victim's system, triggers an out-of-bounds memory write, potentially corrupting process memory. Exploitation requires user interaction — the victim must open or process the malicious file — but no privileges are required, and the attack can be delivered over the network. Apple addressed the issue with improved memory handling and input validation in macOS Sequoia 15.6 (Apple Advisory, Github Advisory).
Successful exploitation can result in process memory corruption, with potential high impacts on confidentiality, integrity, and availability of the affected system. An attacker who tricks a user into opening a malicious image or USD file could disclose sensitive memory contents, corrupt application state, or potentially achieve arbitrary code execution within the context of the affected process. The vulnerability is scoped to the local system but could serve as a stepping stone for further exploitation if chained with other vulnerabilities (Apple Advisory, Github Advisory).
/Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/ referencing Model I/O framework (ModelIO.framework) with out-of-bounds access or memory corruption signals..usd, .usda, .usdc, .usdz, .png, .jpg, etc.) in user download directories or temporary folders from unknown sources.Apple has released macOS Sequoia 15.6 (released July 29, 2025), which addresses CVE-2025-43219 with improved memory handling. Users should update to macOS Sequoia 15.6 or later immediately via System Settings > General > Software Update. As a precautionary measure, users should avoid opening image or USD files from untrusted or unknown sources until the patch is applied (Apple Advisory).
The vulnerability was noted in the SANS Internet Storm Center diary covering the macOS Sequoia 15.6 release, which highlighted the breadth of security fixes in the update. The Zero Day Initiative published an advisory (ZDI-25-676) acknowledging the researcher Michael DePlante's discovery. CIS Security also issued an advisory noting multiple vulnerabilities in Apple products patched in this release that could allow for arbitrary code execution (CIS Advisory, ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."