CVE-2025-43524: Buffer Overflow
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
Other sources
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. A memory corruption issue was addressed with improved input validation.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28959
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28922
- CVE-2026-28936
- CVE-2026-28915
- CVE-2026-43659
- CVE-2026-28923
- CVE-2026-28925
- CVE-2025-43524
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28978
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28908
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28906
- CVE-2026-28840
- CVE-2026-43656
- CVE-2026-39870
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28996
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
- CVE-2026-28878
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-28848
- CVE-2026-28974
- CVE-2025-46288
- CVE-2025-43539
- CVE-2025-43523
- CVE-2025-43519
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-46289
- CVE-2025-46297
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46287
- CVE-2025-46283
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43542
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-46278
- CVE-2025-46279
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-46291
- CVE-2025-5918
- CVE-2025-43513
- CVE-2025-46276
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43509
- CVE-2025-43410
- CVE-2025-43428
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-46277
- CVE-2025-43538
- CVE-2025-46290
- CVE-2025-43514
- CVE-2025-43527
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
- CVE-2025-46282
- CVE-2025-43541
- CVE-2025-43536
- CVE-2025-43535
- CVE-2025-46298
- CVE-2025-43501
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46299
- CVE-2025-43511
Frequently Asked Questions
What is the severity of CVE-2025-43524?
The severity of CVE-2025-43524 is high, with a CVSS score of 8.8.
What types of issues does CVE-2025-43524 address?
CVE-2025-43524 addresses an access issue related to sandbox restrictions and a buffer overflow due to improved bounds checking.
How do I fix CVE-2025-43524?
To fix CVE-2025-43524, update to macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, or macOS Tahoe 26.2.
What software is affected by CVE-2025-43524?
CVE-2025-43524 affects Apple macOS, including macOS Sequoia, macOS Sonoma, and macOS Tahoe.
What vulnerabilities are associated with CVE-2025-43524?
CVE-2025-43524 is associated with buffer overflow, input validation, and race condition vulnerabilities.