
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43539 is a memory corruption vulnerability in Apple's AppleJPEG component caused by improper bounds checks during file processing. It affects a wide range of Apple platforms prior to their respective patched versions: iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. The vulnerability was discovered by Michael Reeves (@IntegralPilot) and publicly disclosed on December 12, 2025, when Apple released the corresponding security updates. It carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory - macOS Sequoia, Apple Advisory - macOS Sonoma).
The root cause is classified as CWE-787 (Out-of-bounds Write) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), residing in Apple's proprietary AppleJPEG image processing library. When a user or application processes a specially crafted file (likely a malformed JPEG), the library fails to perform adequate bounds validation, resulting in a write operation beyond the allocated memory buffer. The attack vector is network-accessible with low attack complexity, requiring only user interaction (e.g., opening or previewing a malicious file) and no privileges. Apple addressed the issue by implementing improved bounds checks in the affected component (Apple Advisory - macOS Sequoia, Apple Advisory - iOS 26.2).
Successful exploitation of this vulnerability can result in memory corruption, which may lead to arbitrary code execution on the affected device with the privileges of the application processing the file. The high CVSS score reflects full impact across confidentiality, integrity, and availability — an attacker could potentially read sensitive data, modify system state, or crash the affected process. Given the broad scope of affected platforms (iPhone, iPad, Mac, Apple Watch, Apple TV, Apple Vision Pro), the attack surface is significant across both consumer and enterprise environments (Apple Advisory - macOS Sonoma, Apple Advisory - visionOS 26.2).
.crash files in ~/Library/Logs/DiagnosticReports/ on macOS) referencing AppleJPEG or related image processing frameworks with memory access violations or out-of-bounds write signals (e.g., EXC_BAD_ACCESS, SIGSEGV).Apple has released patches across all affected platforms. Users should update to the following versions or later: macOS Sonoma 14.8.3, macOS Sequoia 15.7.3, iOS 18.7.3 / iPadOS 18.7.3, iOS 26.2 / iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. No configuration-based workaround is available; updating to a patched OS version is the only remediation. As an interim precaution, users should avoid opening image files from untrusted or unknown sources (Apple Advisory - macOS Sequoia, Apple Advisory - macOS Sonoma, Apple Advisory - iOS 26.2).
The vulnerability was credited to researcher Michael Reeves (@IntegralPilot), who was acknowledged across multiple Apple security advisories. Security vendors including Check Point and Fortinet added detection coverage for this CVE shortly after disclosure. The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Apple products, including this one, could allow for arbitrary code execution. Community coverage was largely routine, with aggregators and vulnerability databases (Vulners, VulDB, CIRCL) cataloging the issue without significant alarm given the absence of active exploitation (CIS Advisory, Apple Advisory - macOS Sequoia).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."