HomeSecurityApple Vulnerability: PoC Exploit released for zero-day bug

Apple Vulnerability: PoC Exploit Released for Zero-Day Bug

Apple Vulnerability: A detailed proof-of-concept (PoC) exploit and a comprehensive vulnerability analysis have been released for CVE-2025-43300, a critical zero-click (remote code execution) vulnerability affecting Apple.

Apple zero-day PoC exploit vulnerability

The vulnerability, discovered in Apple's implementation of JPEG Lossless Decompression within RawCamera.bundle, allows attackers to achieve code execution without any user interaction, via maliciously crafted DNG (Digital Negative) files.

Ευπάθεια Apple: Μεγάλος κίνδυνος για τους χρήστες

The vulnerability represents a significant security threat as it allows zero-click exploitation through Apple's automatic image processing system

See also: Docker Desktop Windows: Vulnerability leads to system compromise

Researcher b1n4r1b01 published detailed technical analysis and exploitation steps, revealing that the vulnerability stems from a buffer overflow condition in the JPEG lossless decompression routine within RawCamera.bundle. The attack mechanism exploits a mismatch between metadata declarations and actual image data.

Specifically, the vulnerability occurs when a DNG file declares SamplesPerPixel = 2 in SubIFD but contains only 1 element in the SOF3 (Start of Frame 3) block of embedded JPEG lossless data. This inconsistency causes an out-of-bounds write during decompression, allowing attackers to corrupt memory and potentially execute malicious code.

The proof-of-concept exploit for the Apple vulnerability requires minimal modifications to a legitimate DNG file (making it highly vulnerable). Attackers only need to change two specific bytes: changing offset 0x2FD00 from 01 to 02 (modifying SamplesPerPixel) and offset 0x3E40B from 02 to 01 (changing the SOF3 element count). These precise modifications create the critical mismatch that triggers the vulnerability.

Apple Vulnerability: PoC Exploit Released for Zero-Day Bug

The vulnerability exploits fundamental assumptions in Apple's TIFF/DNG parsing engine and its interaction with JPEG lossless compression. DNG files, based on the open-source raw image format specification from Adobe, use the TIFF container structure with embedded JPEG lossless compressed image data in SubIFDs.

See also: GeoServer: Critical vulnerability allows remote code execution

The attack exploits the complex interaction between multiple file format standards. The TIFF header structure contains an Image File Directory (IFD) with 12-byte directory entries that specify tags, types, measurements, and values. The Apple vulnerability specifically targets the SamplesPerPixel tag (0x0115) within SubIFDs that reference JPEG lossless compressed data marked with a Compression tag value of 7.

When the decompression routine processes JPEG data, it relies on the SOF3 marker (0xFFC3) to determine the actual element structure. The SOF3 segment contains critical metadata, including precision, dimensions, and, most importantly, the element count. The vulnerability occurs when this element count disagrees with the previously declared SamplesPerPixel value, causing the decompression algorithm to write beyond the allocated buffer boundaries.

The RawCamera.bundle, which handles various raw image formats on iOS, lacks symbol information, making reverse engineering a challenge. However, the researcher notes that not all DNG files with JPEG lossless compression reach the vulnerable code path. Specific conditions are required that align with the provided proof-of-concept sample.

Apple acknowledges that the CVE-2025-43300 vulnerability has been used in sophisticated attacks targeting specific individuals. Its zero-click nature makes it particularly attractive for targeted surveillance operations, as it requires no interaction with victims beyond downloading the malicious file.

See also: Mozilla Firefox 142: Fix critical vulnerabilities

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Apple Vulnerability: PoC Exploit Released for Zero-Day Bug
PoC Exploit Released for zero-day Apple vulnerability

The vulnerability affects multiple Apple platforms, including iOS 18.6.1, iPadOS 18.6.1, and various macOS versions. Apple has released fixes for iOS 18.6.2, iPadOS 18.6.2, macOS Sequoia 15.6.1, and earlier macOS versions.

The CVE-2025-43300 vulnerability demonstrates how critical zero-click vulnerabilities are, especially when they affect widely used platforms like iOS and macOS. The fact that only a few changes to a DNG file are enough to trigger the exploit makes the threat particularly serious for users. Apple’s prompt release of fixes is crucial, but the incident highlights the need for continued vigilance against sophisticated attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS