Apple has backported a critical fix for a high-severity security vulnerability, CVE-2025-43300, that has been actively exploited in the wild. The flaw, affecting the ImageIO component, involves an out-of-bounds write that could allow attackers to corrupt memory by processing a malicious image. While Apple first addressed the issue in its latest software versions, the company has now released updates for older supported devices in a bid to close dangerous attack vectors.
What’s the Key News
- Vulnerability details: CVE-2025-43300 has a CVSS score of 8.8 and stems from ImageIO. A maliciously crafted image file processed by the component could trigger memory corruption.
- Real-world exploitation: Apple confirmed that the vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals.”
- Chained attack vector via WhatsApp: Another vulnerability, CVE-2025-55177 (CVSS 5.4), in WhatsApp for iOS and macOS, is reported to have been chained with CVE-2025-43300 in spyware attacks. Fewer than 200 individuals are believed to be targeted.
- Affected versions & backports: While the fix was first delivered in recent OS updates (e.g., iOS 18.6.2, iPadOS 18.6.2, macOS Ventura 13.7.8, Sonoma 14.7.8, Sequoia 15.6.1), Apple has now backported the patch to older OS versions, including iOS 16.7.12, 15.8.5, and corresponding iPadOS versions covering legacy devices like iPhone 6s/7, iPad Air 2, iPod touch (7th gen) etc.
- Other security fixes: The updates also address a broad slate of other vulnerabilities: from authorization problems in IOKit, keystroke monitoring via LaunchServices, to sandbox permissions, WebKit/ Safari issues, and privilege escalation in DiskArbitration.
Background Context
ImageIO is a core Apple component used to interpret and render images. Out-of-bounds write flaws (writing data outside allocated memory buffers) are dangerous because they often lead to unexpected behavior, crashes, or even arbitrary code execution, should an attacker chain them with other weaknesses. Older devices are especially at risk, as they might no longer receive frequent security patches—or may run outdated OS versions.
The chaining of vulnerabilities—e.g. a flaw in WhatsApp plus CVE-2025-43300—is a classic model in sophisticated spyware and targeted attacks. Attackers often exploit a less privileged bug (such as in an app that can be induced to process a malicious file) together with a system vulnerability to escalate access or persist on a device.
Expert Insights
Although Apple did not name specific attackers or expose full technical details on how the exploit works in the field, the company’s acknowledgment that “specific targeted individuals” were impacted suggests state-level or highly capable adversaries. Security researchers commenting on similar past vulnerabilities warn that ImageIO and other media processing libraries are frequent attack surfaces because they routinely parse untrusted content (images, videos) both from the web and via messaging apps.
Furthermore, backporting fixes to older OS versions demonstrates Apple’s recognition that many devices in the field remain vulnerable and need retrospective protection. This is especially important with legacy devices that users might not update often or cannot update to the latest OS due to hardware constraints.
Conclusion
CVE-2025-43300 is a serious vulnerability actively exploited in the wild and chained with other weaknesses in apps like WhatsApp. Apple’s decision to not only patch its newest operating systems but also backport fixes to older versions is a strong move to mitigate the risk across its device ecosystem. Users of all supported Apple devices—from the latest models down to older hardware—should install updates immediately.
Please subscribe to the Newsletter so that you do not miss any critical update
