Apple Security Advisories · July 2025 — Apple Security Advisories
98 advisories 98 CVEs 3 EXPLOITED

Apple-vendor CVEs for 2025-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2025-6558

OtherExploitedCISA KEV listedHIGH2025-07-15

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-6558

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-48384

OtherExploitedCISA KEV listedHIGH2025-07-08

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (C...

CVEs:CVE-2025-48384

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2025-31277

visionOSExploitedCISA KEV listedCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2025-31277

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24119

macOSActive exploitation (sightings)CRITICAL2025-07-29

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

CVEs:CVE-2025-24119

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31267

OtherActive exploitation (sightings)MEDIUM2025-07-10

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.

CVEs:CVE-2025-31267

Affected products

ProductStatusVendorPackageEcosystem
app_store_connect affected apple
Upstream advisory

CVE-2025-43284

macOSActive exploitation (sightings)MEDIUM2025-07-29

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-43284

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-6965

OtherCoalition ESS > 63%CRITICAL2025-07-15

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

CVEs:CVE-2025-6965

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24224

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to cause unexpected system term...

CVEs:CVE-2025-24224

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43227

visionOSPoC exploitHIGH2025-07-29

This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user ...

CVEs:CVE-2025-43227

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31278

visionOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory...

CVEs:CVE-2025-31278

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31281

visionOSPoC exploitCRITICAL2025-07-29

An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2025-31281

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-43186

visionOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Parsing a file may lead to an unexpected app t...

CVEs:CVE-2025-43186

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31273

visionOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2025-31273

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43216

visionOSPoC exploitCRITICAL2025-07-29

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may...

CVEs:CVE-2025-43216

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43234

visionOSPoC exploitCRITICAL2025-07-29

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected...

CVEs:CVE-2025-43234

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43212

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari ...

CVEs:CVE-2025-43212

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43214

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari ...

CVEs:CVE-2025-43214

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31279

iPadOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to fingerprint the user.

CVEs:CVE-2025-31279

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-43223

visionOSPoC exploitHIGH2025-07-29

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. A non-privileg...

CVEs:CVE-2025-43223

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43240

macOSPoC exploitMEDIUM2025-07-29

A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.

CVEs:CVE-2025-43240

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-43209

visionOSPoC exploitCRITICAL2025-07-29

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing ...

CVEs:CVE-2025-43209

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43228

iPadOSPoC exploitMEDIUM2025-07-29

The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2025-43228

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2025-43220

iPadOSPoC exploitCRITICAL2025-07-29

This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

CVEs:CVE-2025-43220

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-43261

macOSPoC exploitCRITICAL2025-07-29

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVEs:CVE-2025-43261

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43222

iPadOSPoC exploitCRITICAL2025-07-29

A use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

CVEs:CVE-2025-43222

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-43193

macOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.

CVEs:CVE-2025-43193

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43189

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to read kernel memory.

CVEs:CVE-2025-43189

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43194

macOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-43194

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43199

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-43199

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43213

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari ...

CVEs:CVE-2025-43213

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Safari affected Apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43232

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2025-43232

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31229

iPadOSPoC exploitCRITICAL2025-07-29

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.

CVEs:CVE-2025-31229

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-43253

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to launch arbitrary binaries on a trusted device.

CVEs:CVE-2025-43253

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43233

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app acting as a HTTPS proxy could get access to sensitive user data.

CVEs:CVE-2025-43233

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43243

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-43243

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43184

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A shortcut may be able to bypass sensitive Shortcuts app settings.

CVEs:CVE-2025-43184

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43245

macOSPoC exploitCRITICAL2025-07-29

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

CVEs:CVE-2025-43245

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43192

macOSPoC exploitCRITICAL2025-07-29

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mode turned on.

CVEs:CVE-2025-43192

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43198

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access protected user data.

CVEs:CVE-2025-43198

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43273

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2025-43273

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43275

macOSPoC exploitCRITICAL2025-07-29

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVEs:CVE-2025-43275

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43244

macOSPoC exploitCRITICAL2025-07-29

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-43244

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24188

macOSPoC exploitHIGH2025-07-29

A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVEs:CVE-2025-24188

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-43237

macOSPoC exploitCRITICAL2025-07-29

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-43237

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43252

macOSPoC exploitMEDIUM2025-07-29

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access sensitive user data when resolving symlinks.

CVEs:CVE-2025-43252

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43247

macOSPoC exploitMEDIUM2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app with root privileges may be able to modify the contents of system files.

CVEs:CVE-2025-43247

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43219

macOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

CVEs:CVE-2025-43219

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43202

iPadOSPoC exploitCRITICAL2025-07-29

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

CVEs:CVE-2025-43202

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-31276

iPadOSPoC exploitMEDIUM2025-07-29

This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.

CVEs:CVE-2025-31276

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-43264

macOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

CVEs:CVE-2025-43264

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43211

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.

CVEs:CVE-2025-43211

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43210

visionOSPoC exploitMEDIUM2025-07-29

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing ...

CVEs:CVE-2025-43210

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43276

macOSPoC exploitMEDIUM2025-07-29

A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time.

CVEs:CVE-2025-43276

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43229

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.

CVEs:CVE-2025-43229

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-43265

visionOSPoC exploitMEDIUM2025-07-29

An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose interna...

CVEs:CVE-2025-43265

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43277

visionOSPoC exploitCRITICAL2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.8, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted audio file may lead to memory corrupt...

CVEs:CVE-2025-43277

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43259

macOSPoC exploitMEDIUM2025-07-29

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user info...

CVEs:CVE-2025-43259

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31280

macOSPoC exploitCRITICAL2025-07-29

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted file may lead to heap corruption.

CVEs:CVE-2025-31280

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43224

visionOSPoC exploitHIGH2025-07-29

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination ...

CVEs:CVE-2025-43224

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-43267

macOSPoC exploitMEDIUM2025-07-29

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. An app may be able to access sensitive user data.

CVEs:CVE-2025-43267

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43191

macOSPoC exploitHIGH2025-07-29

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.

CVEs:CVE-2025-43191

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43250

macOSPoC exploitMEDIUM2025-07-29

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVEs:CVE-2025-43250

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43196

macOSPoC exploitCRITICAL2025-07-29

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.

CVEs:CVE-2025-43196

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43206

macOSPoC exploitMEDIUM2025-07-29

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.

CVEs:CVE-2025-43206

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43226

visionOSPoC exploitMEDIUM2025-07-29

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image m...

CVEs:CVE-2025-43226

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43239

macOSPoC exploitHIGH2025-07-29

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2025-43239

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43187

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Running an hdiutil command may unexpectedly execute arbitrary code.

CVEs:CVE-2025-43187

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43215

macOSPoC exploitMEDIUM2025-07-29

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclosure of process memory.

CVEs:CVE-2025-43215

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43188

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-43188

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43248

macOSPoC exploitCRITICAL2025-07-29

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-43248

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43249

macOSPoC exploitCRITICAL2025-07-29

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.

CVEs:CVE-2025-43249

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43254

macOSPoC exploitHIGH2025-07-29

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2025-43254

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43221

visionOSPoC exploitHIGH2025-07-29

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination ...

CVEs:CVE-2025-43221

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-43230

visionOSPoC exploitHIGH2025-07-29

The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.

CVEs:CVE-2025-43230

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31243

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to gain root privileges.

CVEs:CVE-2025-31243

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43256

macOSPoC exploitCRITICAL2025-07-29

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to gain root privileges.

CVEs:CVE-2025-43256

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43218

macOSPoC exploitMEDIUM2025-07-29

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.

CVEs:CVE-2025-43218

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43260

macOSPoC exploitMEDIUM2025-07-29

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.

CVEs:CVE-2025-43260

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43266

macOSPoC exploitMEDIUM2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.

CVEs:CVE-2025-43266

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43225

iPadOSPoC exploitMEDIUM2025-07-29

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

CVEs:CVE-2025-43225

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-43195

macOSPoC exploitMEDIUM2025-07-29

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

CVEs:CVE-2025-43195

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43246

macOSPoC exploitMEDIUM2025-07-29

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access sensitive user data.

CVEs:CVE-2025-43246

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43241

macOSPoC exploitMEDIUM2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to read files outside of its sandbox.

CVEs:CVE-2025-43241

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43270

macOSPoC exploitHIGH2025-07-29

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may gain unauthorized access to Local Network.

CVEs:CVE-2025-43270

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43197

macOSPoC exploitMEDIUM2025-07-29

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

CVEs:CVE-2025-43197

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31275

macOSPoC exploitMEDIUM2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to launch any installed app.

CVEs:CVE-2025-31275

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43217

iPadOSPoC exploitMEDIUM2025-07-29

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.

CVEs:CVE-2025-43217

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-43255

macOSPoC exploitLOW2025-07-29

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-43255

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43238

macOSPoC exploitCRITICAL2025-07-29

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-43238

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43235

macOSPoC exploitHIGH2025-07-29

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.

CVEs:CVE-2025-43235

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43257

macOSPoC exploitHIGH2025-07-29

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.

CVEs:CVE-2025-43257

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43236

macOSPoC exploitLOW2025-07-29

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

CVEs:CVE-2025-43236

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43268

macOSPoC exploitCRITICAL2025-07-29

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-43268

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43251

macOSPoC exploitMEDIUM2025-07-29

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain access to Keychain items.

CVEs:CVE-2025-43251

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43185

macOSPoC exploitMEDIUM2025-07-29

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access protected user data.

CVEs:CVE-2025-43185

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43282

visionOSPoC exploitCRITICAL2025-07-29

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able ...

CVEs:CVE-2025-43282

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-43313

macOSPoC exploitMEDIUM2025-07-29

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

CVEs:CVE-2025-43313

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43274

macOSPoC exploitMEDIUM2025-07-29

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2025-43274

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.