Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Reverse engineering of Apple's iOS 0-click CVE-2025-43300: 2 bytes that make size matter

blog.quarkslab.com | vulnerability | Critical | Actively exploited | CVE-2025-43300 | #reverse-engineering | #ios | #apple | #cve-2025-43300 | #imageio | #zero-click

Summary

Quarkslab's root-cause analysis of CVE-2025-43300, the iOS ImageIO out-of-bounds write exploited in zero-click campaigns; patch diffing points to RawCamera and DNG parsing.
CVSS
10
Published
Collected

original ↗

Related coverage

back