CVE-2025-43344: Buffer Overflow
Published Sep 15, 2025
·Updated
AirPort. A permissions issue was addressed with additional restrictions.
Credit
an anonymous researcher, Mickey Jin@@patch1t, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Michael Reeves@@IntegralPilot, Csaba Fitzl@@theevilbit(Kandji), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), @@zlluny(Trend Micro Zero Day Initiative), 이동하 (Lee Dong Ha)(SSA Lab), Keisuke Hosoda, Viktor Oreshkin, Dawuge(Shuffle Team), Noah Gregory (wts.dev), CVE-2025-6965, JZ, Seo Hyun-gyu@@wh1te4ever, Luke Roberts@@rookuu, Jaydev Ahire, Big Bear, Ignacio Sanmillan@@ulexec, Mike Cardwell(grepular), Bob Lord, Nikita Sakalouski, Rosyna Keller(Totally Not Malicious Software), Guilherme Rambo(Best Buddy Apps), Philipp Baldauf, Minghao Lin@@Y1nKoc, Lyutoon@@Lyutoon_, YingQi Shi@@Mas0n, Tom Brzezinski, Abhay Kailasia@@abhay_kailasia(C), KPC(Cisco Talos), Evan Waelde, 정답이 아닌 해답, Richard Hyunho Im@@richeeta, Pawel Wylecial(REDTEAM), Kirin@@Pwnrin, ABC Research s.r.o., Nolan Astrein(Kandji), Mickey Jin@@patch1t(Cisco Talos), Kirin@@Pwnrin(Cisco Talos), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Zhongquan Li@@Guluisacat, Bilal Siddiqui, Shantanu Thakur, Wang Yu(Cyberserval), Anonymous(Trend Micro Zero Day Initiative), Yiğit Can YILMAZ@@yilmazcanyigit, Ye Zhang@@VAR10CK(Baidu Security), Nathaniel Oh@@calysteon, Gergely Kalman@@gergely_kalman, Hikerell (Loadshine Lab), Rodolphe Brunetti@@eisw0lf(Lupus Nova), LFY@@secsys(Fudan University), CVE-2025-40909, Zhongcheng Li(IES Red Team of ByteDance), @@zlluny, CVE-2024-27280, @@RenwaX23, Ye Zhang(Baidu Security), pattern-f@@pattern_F_, Kirin@@Pwnrin(Computer Science), Cristian Dinca(Computer Science), Romania, Ferdous Saljooki@@malwarezoo(Jamf), Justin Elliot Fu, Pyrophoria(GrapheneOS), an anonymous researcher(GrapheneOS), James J Kalafus, Michel Migdal, ken super, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova)
Affected Software
12 affected componentsFixes available
Apple macOS Tahoe<26
26
Apple tvOS<26
26
Apple iOS<26
26
Apple iPadOS<26
26
Apple WatchOS<26
26
Apple visionOS<26
26
Apple iPadOS<26.0
Apple iPhone OS<26.0
Apple macOS<26.0
Apple tvOS<26.0
Apple visionOS<26.0
Apple WatchOS<26.0
Event History
Sep 15, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43344?
CVE-2025-43344 has been assessed as a high severity vulnerability affecting multiple Apple operating systems.
2
How do I fix CVE-2025-43344?
To fix CVE-2025-43344, ensure you update your devices to the latest version of macOS Tahoe, tvOS, iOS, iPadOS, watchOS, or visionOS.
3
What types of issues does CVE-2025-43344 address?
CVE-2025-43344 addresses a permissions issue, a buffer overflow, and an out-of-bounds access issue.
4
Which products are affected by CVE-2025-43344?
CVE-2025-43344 affects Apple macOS Tahoe, tvOS, iOS, iPadOS, watchOS, and visionOS up to version 26.
5
What systems need to be updated for CVE-2025-43344?
Update all affected Apple devices running macOS Tahoe, tvOS, iOS, iPadOS, watchOS, or visionOS to protect against CVE-2025-43344.