CVE-2025-43300
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
10 articles
EPSS Score
Source: FIRST.org · 2026-05-24
4.42%
probability
This CVE has a 4.42% probability
of being exploited in the next 30 days.
0%
Top 89.1th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroMemory corruption in ImageIO
Attack Intelligence
Google Project Zero
Patched
Aug. 20, 2025
Reported by
Apple
Root Cause Analysis
???
Exploits & PoC
hunters-sec/CVE-2025-43300
This is POC for IOS 0click CVE-2025-43300
110
7amzahard/CVE-2025-43300
CVE-2025-43300: iOS/macOS DNG Image Processing Memory Corruption
10
PwnToday/CVE-2025-43300
CVE-2025-43300: iOS/macOS DNG Image Processing Memory Corruption
6
ticofookfook/CVE-2025-43300
PoC CVE-2025-43300 — ticofookfook/CVE-2025-43300
3
Dark-life944/CVE-2025
This is POC for IOS 0click CVE-2025-43300
1
5 repos — triés par ⭐
Rechercher sur GitHub ↗
Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks
TheHackerNews
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
BleepingComputer
Dec 12, 2025
Apple fixes new zero-day flaw exploited in targeted attacks
BleepingComputer
Aug 20, 2025
Apple backports zero-day patches to older iPhones and iPads
BleepingComputer
Sep 16, 2025
Samsung patches actively exploited zero-day reported by WhatsApp
BleepingComputer
Sep 12, 2025
WhatsApp patches vulnerability exploited in zero-day attacks
BleepingComputer
Aug 29, 2025
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
TheHackerNews
Dec 13, 2025
Signal Intelligence
Confidence
92%
EPSS
4.42%
Mentions
10
Last Seen
Dec 13, 2025
CNA Information
Analyst Note
This CVE is a confirmed zero-day with CVSS 10.0 criticality that has been actively exploited in sophisticated targeted attacks against specific individuals, as acknowledged by Apple. The vulnerability affects a wide range of iOS/iPadOS versions with official patches released, corroborated by multiple credible security news sources including BleepingComputer reporting on the exploited zero-day status.
Threat Actors 22
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
Watchdog
apt_group
🇨🇳 CN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
[Unnamed group]
apt_group
🇨🇳 CN
RomCom
apt_group
Financial gain
🇷🇺 RU
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
Void Rabisu
apt_group
Financial gain
🇷🇺 RU
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Stealth Falcon
apt_group
Information theft and espionage
🇦🇪 AE
Silent Crow
apt_group
🇺🇦 UA
Pat Bear
apt_group
🇸🇾 SY
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
UNION SPIDER
apt_group
🇷🇺 RU
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Storm-2460
apt_group
🇷🇺 RU
Triage Info
Decided atMar 03, 2026