VDB
CVE-2025-43300
CVE-2025-43300
PUBLISHED
KEV
Une vulnérabilité a été découverte dans les produits Apple. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Apple indique que la vulnérabilité CVE-2025-43300 est activement exploitée dans le cadre d'attaques ciblées.
EPSS 4.42% · 89.2th percentile
Risk Scores
EPSS Score
4.42%
89.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | iOS | |
| Apple | iPadOS | |
| Apple | macOS |
Exploit Intelligence
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- The exploit code for CVE-2025-43300. (github-poc)
- Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then WebKit(CVE-2025-24201) and Core Media(CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction. (github-poc-repo)
…and 337 more exploits
Timeline
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 20, 2025 PoC Published
- Aug 21, 2025 CVE Published
- Aug 21, 2025 CISA KEV Added
- Aug 21, 2025 EPSS Score
- Aug 21, 2025 Coalition ESS Score
References
- https://cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0791/ advisory
- https://support.apple.com/en-us/125112 advisory
- https://support.apple.com/en-us/125116 advisory
- https://support.apple.com/en-us/125110 advisory
- https://support.apple.com/en-us/125115 advisory
- https://support.apple.com/en-us/125141 advisory
- https://support.apple.com/en-us/125117 advisory
- https://support.apple.com/en-us/125114 advisory
- https://support.apple.com/en-us/125108 advisory
- https://support.apple.com/en-us/125111 advisory
- https://support.apple.com/en-us/125109 advisory
- https://support.apple.com/en-us/125142 advisory
- https://support.apple.com/en-us/125113 advisory
- https://cert.ssi.gouv.fr/avis/CERTFR-2025-AVI-0716/ advisory
- https://support.apple.com/en-us/124925 advisory
- https://support.apple.com/en-us/124928 advisory
- https://support.apple.com/en-us/124926 advisory
- https://support.apple.com/en-us/124929 advisory
- https://support.apple.com/en-us/124927 advisory