CVE-2025-43346: Buffer Overflow
AirPort. A permissions issue was addressed with additional restrictions.
Other sources
AMD. A buffer overflow was addressed with improved bounds checking.
— Apple
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
— MITRE
AppKit. The issue was resolved by blocking unsigned services from launching on Intel Macs.
— Apple
Apple Neural Engine. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
Apple Online Store Kit. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43344
- CVE-2025-43317
- CVE-2025-43346
- CVE-2025-43361
- CVE-2025-43360
- CVE-2025-43354
- CVE-2025-43303
- CVE-2025-43357
- CVE-2025-43323
- CVE-2025-43349
- CVE-2025-43372
- CVE-2025-43338
- CVE-2025-43302
- CVE-2025-31255
- CVE-2025-43359
- CVE-2025-43345
- CVE-2025-43362
- CVE-2025-43365
- CVE-2025-43355
- CVE-2025-43203
- CVE-2025-43309
- CVE-2025-46306
- CVE-2025-31254
- CVE-2025-43329
- CVE-2025-43358
- CVE-2025-30468
- CVE-2025-43190
- CVE-2025-6965
- CVE-2025-43347
- CVE-2025-43356
- CVE-2025-43272
- CVE-2025-43343
- CVE-2025-43342
- CVE-2025-43419
- CVE-2025-43376
- CVE-2025-43368
- CVE-2025-43288
- CVE-2025-43208
- CVE-2025-43312
- CVE-2025-43321
- CVE-2025-31268
- CVE-2025-43331
- CVE-2025-43340
- CVE-2025-43337
- CVE-2025-43320
- CVE-2025-43285
- CVE-2025-43330
- CVE-2025-43451
- CVE-2025-43307
- CVE-2025-43403
- CVE-2025-43292
- CVE-2025-24088
- CVE-2025-43305
- CVE-2025-43290
- CVE-2025-43289
- CVE-2025-46284
- CVE-2025-43316
- CVE-2025-31271
- CVE-2025-31270
- CVE-2025-43326
- CVE-2025-43283
- CVE-2025-46280
- CVE-2025-43325
- CVE-2025-43287
- CVE-2025-43366
- CVE-2025-43299
- CVE-2025-43295
- CVE-2025-43353
- CVE-2025-43294
- CVE-2025-43319
- CVE-2025-43315
- CVE-2025-43207
- CVE-2025-43279
- CVE-2025-43301
- CVE-2025-43298
- CVE-2025-46310
- CVE-2025-40909
- CVE-2025-43297
- CVE-2025-31269
- CVE-2025-43204
- CVE-2024-27280
- CVE-2025-43327
- CVE-2025-43328
- CVE-2025-43318
- CVE-2025-46307
- CVE-2025-31259
- CVE-2025-43332
- CVE-2025-43293
- CVE-2025-43291
- CVE-2025-43286
- CVE-2025-43369
- CVE-2025-43367
- CVE-2025-43333
- CVE-2025-24197
- CVE-2025-43341
- CVE-2025-43314
- CVE-2025-43304
- CVE-2025-43306
- CVE-2025-43296
- CVE-2025-43311
- CVE-2025-43308
- CVE-2025-43262
- CVE-2025-43310
Frequently Asked Questions
What is the severity of CVE-2025-43346?
CVE-2025-43346 has been classified as a high severity vulnerability due to its potential exploitation risks in multiple Apple operating systems.
How do I fix CVE-2025-43346?
To fix CVE-2025-43346, users should update their affected Apple devices to the latest versions of macOS, tvOS, iOS, iPadOS, watchOS, or visionOS as specified in the security advisory.
What are the affected versions for CVE-2025-43346?
CVE-2025-43346 affects various Apple operating systems including macOS Tahoe, tvOS, iOS, iPadOS, watchOS, and visionOS up to version 26 and iOS and iPadOS up to version 18.7.
What type of vulnerabilities does CVE-2025-43346 address?
CVE-2025-43346 addresses permissions issues, buffer overflows, and out-of-bounds access vulnerabilities across several Apple software platforms.
Who can be impacted by CVE-2025-43346?
Users of affected Apple devices running the vulnerable versions of the mentioned operating systems can be impacted by CVE-2025-43346.