CVE-2025-43264
macOS vulnerability analysis and mitigation

Overview

CVE-2025-43264 is an out-of-bounds read vulnerability in Apple's Model I/O framework affecting macOS Sequoia versions prior to 15.6. The flaw arises from improper input validation when processing maliciously crafted image or USD (Universal Scene Description) files, which can corrupt process memory or disclose memory contents. It was discovered by Michael DePlante (@izobashi) of Trend Micro Zero Day Initiative and disclosed by Apple on July 29, 2025 alongside the macOS Sequoia 15.6 release. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically an out-of-bounds read in Apple's Model I/O framework — the component responsible for importing, exporting, and manipulating 3D scene data including USD files and images. An attacker can exploit this by crafting a malicious image or USD file that, when parsed by the affected framework, triggers a read beyond the intended memory buffer boundary, potentially exposing adjacent memory contents or corrupting process memory. Exploitation requires user interaction (opening or processing the malicious file), but no privileges are required and the attack can be delivered over the network. Apple addressed the issue with improved input validation and memory handling (Apple Advisory, Github Advisory).

Impact

Successful exploitation can result in disclosure of sensitive process memory contents, process memory corruption, and potentially arbitrary code execution in the context of the application processing the malicious file. The CVSS scoring reflects high confidentiality, integrity, and availability impact, meaning an attacker could potentially read sensitive data from memory, corrupt application state, or cause application crashes. The attack surface is broad as any macOS Sequoia application that processes USD or image files via the Model I/O framework could be affected (Apple Advisory, Github Advisory).

Exploitation steps

  1. Craft malicious file: Create a specially crafted image or USD (Universal Scene Description) file that contains malformed data designed to trigger an out-of-bounds read in Apple's Model I/O framework during parsing.
  2. Deliver the file: Distribute the malicious file to the target via email attachment, web download, shared document, or any other network-accessible channel, since the attack vector is network-based.
  3. Induce user interaction: Social-engineer the victim into opening the malicious file on a macOS Sequoia system running a version prior to 15.6 (e.g., by disguising it as a legitimate 3D asset or image).
  4. Trigger out-of-bounds read: When the victim's system processes the file through the Model I/O framework, the insufficient input validation causes a read operation beyond the intended memory buffer boundary.
  5. Achieve objective: Depending on the specific memory layout, the attacker may obtain disclosure of sensitive memory contents (e.g., pointers, credentials, keys) or trigger memory corruption that could be leveraged for further exploitation such as code execution (Apple Advisory).

Indicators of compromise

  • Process Behavior: Unexpected crashes or terminations of applications that process 3D or image files (e.g., Preview, Reality Composer, or third-party apps using Model I/O) on macOS Sequoia prior to 15.6.
  • File System: Presence of unexpected or unsolicited USD (.usd, .usda, .usdc, .usdz) or image files in user download directories, temporary folders, or email attachment locations.
  • Logs: Application crash reports (in /Library/Logs/DiagnosticReports/ or ~/Library/Logs/DiagnosticReports/) referencing Model I/O or related frameworks with out-of-bounds memory access signals (e.g., EXC_BAD_ACCESS, SIGSEGV).
  • Network: Unusual inbound file transfers or downloads of USD/image files from untrusted or unknown sources preceding application crashes.

Mitigation and workarounds

Apple has released a patch in macOS Sequoia 15.6, which includes improved input validation and memory handling to address this vulnerability. All users running macOS Sequoia versions prior to 15.6 should update immediately via System Settings > General > Software Update. As a temporary workaround prior to patching, users should avoid opening USD files or images from untrusted or unknown sources, and administrators can implement file validation controls or application whitelisting to restrict which applications can process USD files (Apple Advisory).

Community reactions

The Zero Day Initiative published an advisory (ZDI-25-683) shortly after Apple's disclosure, reflecting their role in coordinating the report through researcher Michael DePlante. The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Apple products that could allow for arbitrary code execution, referencing this update. Community coverage has been limited, consistent with the absence of active exploitation or public PoC code (Apple Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management