The issue was addressed with improved input validation. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
No PoCs from references.
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/allinsthon/CVE-2025-43372
- https://github.com/nomi-sec/PoC-in-GitHub