CVE-2025-43218
BaseFortify
Publication date: 2025-07-30
Last updated on: 2025-11-03
Assigner: Apple Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apple | macos | to 15.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds read caused by insufficient input validation when processing USD files. A specially crafted USD file can cause the system to read memory outside the intended bounds, potentially exposing sensitive memory contents.
How can this vulnerability impact me? :
If exploited, this vulnerability may allow an attacker to disclose sensitive memory contents, which could include confidential information, leading to potential data leakage or information exposure.
What immediate steps should I take to mitigate this vulnerability?
The vulnerability is fixed in macOS Sequoia 15.6. To mitigate this vulnerability, update your system to macOS Sequoia 15.6 or later. Avoid processing maliciously crafted USD files until the update is applied.