Apple ImageIO Out-of-Bounds Read Vulnerability Allowing Process Memory Disclosure

Vulnerability

A vulnerability in the ImageIO component of Apple software, including iOS, iPadOS, macOS, tvOS, and watchOS, allows for an out-of-bounds read that can lead to the disclosure of process memory. This issue was addressed with improved input validation. The vulnerability affects several different versions and ranges across the mentioned operating systems.

Impact

Exploitation of this vulnerability can result in the unauthorized disclosure of process memory, potentially allowing for the extraction of sensitive information.

Remediation

Users can update to the latest versions of watchOS, iOS, iPadOS, tvOS, and macOS to address this vulnerability. Specific update instructions can be found on the Apple Support website.

Added: Jul 30, 2025, 1:34 AM
Updated: Jul 30, 2025, 1:34 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.