CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
CVSS Vector
AV:N/AC:L/Au:N/C:N/I:N/A:CApple iOS
OSApple8.08.0.18.0.28.18.1.28.1.38.28.3Apple Itunes
APPApple≤ 12.2Apple Mac Os X
OSApple≤ 10.0.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References
Related vulnerabilities
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product
Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach
CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product
Apple — memory corruption (RCE) w przetwarzaniu strumieni audio
CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki
CVE-2025-24085CRITICAL10.0⚠ KEVPL ✓same product
Use-after-free w Apple iOS/iPadOS/macOS — privilege escalation przez aplikację