CVE-2025-43400: Input Validation
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory.
Other sources
Apple Account. A privacy issue was addressed with improved checks.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. This issue was addressed with improved validation of symlinks.
— Apple
Assets. This issue was addressed with improved entitlements.
— Apple
CloudKit. This issue was addressed with improved validation of symlinks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43400
- CVE-2025-43455
- CVE-2025-43447
- CVE-2025-43462
- CVE-2025-43379
- CVE-2025-43448
- CVE-2025-43436
- CVE-2025-43445
- CVE-2025-43507
- CVE-2025-43444
- CVE-2025-43398
- CVE-2025-43510
- CVE-2025-43520
- CVE-2025-43413
- CVE-2025-43494
- CVE-2025-43496
- CVE-2025-43294
- CVE-2025-43459
- CVE-2025-43503
- CVE-2025-43500
- CVE-2025-43480
- CVE-2025-43458
- CVE-2025-43430
- CVE-2025-43443
- CVE-2025-43440
- CVE-2025-43438
- CVE-2025-43457
- CVE-2025-43434
- CVE-2025-43435
- CVE-2025-43425
- CVE-2025-43433
- CVE-2025-43431
- CVE-2025-43432
- CVE-2025-43429
- CVE-2025-43392
- CVE-2025-43407
- CVE-2025-43386
- CVE-2025-43385
- CVE-2025-43384
- CVE-2025-43383
- CVE-2025-43427
- CVE-2025-43441
Frequently Asked Questions
What is the severity of CVE-2025-43400?
CVE-2025-43400 has been classified as a high severity vulnerability due to the potential for exploitation that can lead to arbitrary code execution.
How do I fix CVE-2025-43400?
You can fix CVE-2025-43400 by updating your system to the latest versions: macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, macOS Sequoia 15.7.1, visionOS 26.0.1, iOS 26.0.1, or iPadOS 26.0.1.
Which products are affected by CVE-2025-43400?
The affected products include macOS Tahoe prior to 26.0.1, macOS Sequoia prior to 15.7.1, iOS prior to 26.0.1 and 18.7.1, and iPadOS prior to 26.0.1 and 18.7.1.
What kind of attack does CVE-2025-43400 involve?
CVE-2025-43400 involves an out-of-bounds write issue that can be exploited through maliciously crafted fonts.
Is there a specific update I need for CVE-2025-43400?
Yes, to resolve CVE-2025-43400, ensure your systems are updated to the specified latest versions mentioned in the security advisories.