cbcvebase.
CVE-2025-43300
published 2025-08-21

CVE-2025-43300: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12…

PriorityP192critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-09-11
Exploited in the wild
EPSS
19.97%
97.1th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Affected

23 ranges
VendorProductVersion rangeFixed in
appleios_15.8.5_and_ipados
appleios_16.7.12_and_ipados
appleios_18.6.2_and_ipados
appleipados< 15.8.515.8.5
appleipados
appleipados>= 16.0 < 16.7.1216.7.12
appleipados>= 17.0 < 17.7.1017.7.10
appleipados>= 18.0 < 18.6.218.6.2
appleiphone_os< 15.8.515.8.5
appleiphone_os>= 16.0 < 16.7.1216.7.12
appleiphone_os>= 17.0 < 18.6.218.6.2
applemacos>= 13.0 < 13.7.813.7.8
applemacos>= 14.0 < 14.7.814.7.8
applemacos>= 15.0 < 15.6.115.6.1
applemacos_sequoia
applemacos_sonoma
applemacos_ventura
facebookwhatsapp_business_for_ios>= 2.22.25.2 < 2.25.21.782.25.21.78
facebookwhatsapp_desktop_for_mac>= 2.22.25.2 < 2.25.21.782.25.21.78
facebookwhatsapp_for_ios>= 2.22.25.2 < 2.25.21.732.25.21.73
whatsappwhatsapp>= 2.22.25.2 < 2.25.21.732.25.21.73
whatsappwhatsapp>= 2.22.25.2 < 2.25.21.782.25.21.78
whatsappwhatsapp_business>= 2.22.25.2 < 2.25.21.782.25.21.78

Detection & IOCsextracted from sources · hover to see the quote

filenameb.so
filenamel.so
filenamelibimagecodec.quram.so
  • CVE-2025-43300 is triggered by processing malicious image files (DNG format); inspect inbound DNG files — especially those with a ZIP archive appended — delivered via messaging apps for anomalous structure.
  • CVE-2025-43300 is an out-of-bounds write in Apple's Image I/O framework; monitor for crashes or unexpected memory corruption events in ImageIO-related processes on iOS/iPadOS/macOS when processing image files.
  • The exploit chain (CVE-2025-55177 + CVE-2025-43300) is zero-click and delivered via WhatsApp linked-device synchronization messages; alert on WhatsApp processes initiating unexpected outbound URL fetches on iOS/macOS.
  • LandFall spyware samples were submitted to VirusTotal starting July 23, 2024, with filenames indicating WhatsApp as the delivery channel; hunt for DNG files delivered via WhatsApp with ZIP data appended.
  • ·No technical details or proof-of-concept for CVE-2025-43300 have been publicly published; exploitation was observed in the wild but attack mechanics beyond the image-file trigger are not yet disclosed.
  • ·The exploit chain targets specific individuals (journalists, lawyers, activists, politicians, senior officials); broad-population detections will have low base-rate signal and should be tuned for high-value targets.
  • ·WhatsApp's own advisory notes that even after patching CVE-2025-55177, the device OS may remain compromised; patching WhatsApp alone is insufficient for already-targeted devices.
  • ·LandFall attribution is murky — infrastructure overlaps with Stealth Falcon (UAE) and naming conventions overlap with NSO/Variston/Cytrox/Quadream, but no confident attribution to a known group has been made.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.