Full Disclosure mailing list archives

APPLE-SA-08-20-2025-4 macOS Sonoma 14.7.8


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Wed, 20 Aug 2025 17:10:30 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-08-20-2025-4 macOS Sonoma 14.7.8

macOS Sonoma 14.7.8 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/124928.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

ImageIO
Available for: macOS Sonoma
Impact: Processing a malicious image file may result in memory
corruption. Apple is aware of a report that this issue may have been
exploited in an extremely sophisticated attack against specific targeted
individuals.
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2025-43300: Apple

macOS Sonoma 14.7.8 may be obtained from the Mac App Store or
Apple's Software Downloads web site:
https://support.apple.com/downloads/

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEhjkl+zMLNwFiCT1o4Ifiq8DH7PUFAmimYcgACgkQ4Ifiq8DH
7PUOSw//YFleAN4ZeDbFoaTUXExV6hUg8maX00duxhRmFyyyXZoHL1a1LGE4kB/6
id359ACUbIcgbqKrn9zBGqFpYS3IBvKe9JB4gYUylwLlmcMhZYDMRpRwbOzPrF0m
NTTCMQT7QeXeLN9Jm8Rb4ktye3lyCt9Gp863ouI1DLmdpU+wP+6hC3B6SiObgI4K
4XjloE6Bx16fTeDR7sx2cf2yBXMbz3rumzfF3Ym+F6nQXlUc4PNNy3DcOos/mLwM
riWRRz+fm6NHFdXHlmWSM3bBV6mvSvhafjRIF+1DhkH7E+MS6mjWzpWjA0AjYBhH
m/3LNwXaeseY/yDWxdvG2PA33d6mX31/f5jghDqQ9OzXMDDEBuJkYwkEXvbZPg7R
oSnO3uLzIBaOStPwkYsz+EsQ7XiSq9tDgQrgpfKuIMwDEHmmzGJO7mU+UA4gPEJ0
fWwNkTu0ZGRrACA94NmlJPa8FIlloFk7Bm/ju/bsKWPc0S4bKoEgjR16lCS6egZt
jTP93/ChR80sEmVBLr/utojVLZt1nMoDb6sTKLDpVzJ4WieuyQFGCMUe0KbSsTGj
bFnb8SAlrU0xLgUz6CwJzPhS519aAV5yZEMzdr5YeHc1EqMII5LZnFHHCaX9ADb3
MlnAtnx9OTMRQpcGJZvcS3GI7Dj91pKNBt03dcV9MWE0558rc4k=
=UC09
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread: