Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
Published: 2025-08-29
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (system crash)
Action: Apply Patch
AI Analysis

Impact

The reported issue is an out-of-bounds read that caused unexpected system termination. The flaw was mitigated with enhanced bounds checking. While the vulnerability does not appear to expose data or enable privilege escalation, it leads to a denial-of-service by crashing the operating system.

Affected Systems

Affected platforms are Apple macOS versions prior to the patch releases documented by Apple. Specifically, all macOS Ventura builds earlier than 13.7.7, all macOS Sonoma builds earlier than 14.7.7, and all macOS Sequoia builds earlier than 15.6 are impacted. Applications running on those systems could trigger the crash if the out-of-bounds condition is met.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is under 1 %, implying that the likelihood of exploitation is low. The vulnerability is not catalogued in the CISA KEV database. Because the flaw appears to be exercised through an improper memory read, the most likely scenario is a malicious application or specially crafted input that triggers the defect; the consequence is purely a denial-of-service via system termination.

Generated by OpenCVE AI on April 28, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the macOS Ventura 13.7.7 update
  • Install the macOS Sonoma 14.7.7 update
  • Install the macOS Sequoia 15.6 update

Generated by OpenCVE AI on April 28, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26196 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.6. An app may be able to cause unexpected system termination.
History

Tue, 28 Apr 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing System Crash on macOS Before 13.7.7

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.6. An app may be able to cause unexpected system termination. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

Tue, 02 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Mon, 01 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura
Vendors & Products Apple
Apple macos
Apple macos Sequoia
Apple macos Sonoma
Apple macos Ventura

Fri, 29 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Aug 2025 00:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.6. An app may be able to cause unexpected system termination.
References

Subscriptions

Apple Macos Macos Sequoia Macos Sonoma Macos Ventura
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:22:14.768Z

Reserved: 2025-04-16T15:24:37.101Z

Link: CVE-2025-43284

cve-icon Vulnrichment

Updated: 2025-08-29T13:20:41.107Z

cve-icon NVD

Status : Modified

Published: 2025-08-29T01:15:35.133

Modified: 2026-04-02T19:20:19.943

Link: CVE-2025-43284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T00:30:15Z

Weaknesses