Apple has released emergency security updates to fix CVE-2025-43300, a zero-day vulnerability actively exploited in highly targeted attacks against select individuals. The flaw resides in ImageIO, the system component responsible for parsing common image formats across Apple platforms. According to Apple’s advisory, processing a maliciously crafted image file could trigger an out-of-bounds write, leading to memory corruption and potential arbitrary code execution. Apple says it is aware of reports that the issue was used in an “extremely sophisticated attack” against specific targets.
What’s affected—and what’s fixed
CVE-2025-43300 impacts current Apple operating systems on iPhone, iPad, and Mac. Apple shipped patches in the following releases:
- iOS 18.6.2 and iPadOS 18.6.2
- iPadOS 17.7.10 (for devices remaining on iPadOS 17)
- macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, and macOS Ventura 13.7.8
In all cases, Apple states the bug was addressed by improved bounds checking inside ImageIO. These version numbers and the mitigation approach are documented in Apple’s security notes and the NVD entry for CVE-2025-43300.
How the attack works
Although technical details are limited (to avoid copycat exploitation), multiple security outlets report that attackers can trigger the vulnerability via zero-click or low-click vectors—for example, when a device automatically previews or indexes an image in messaging apps, email, or web content. Because ImageIO is a shared subsystem, the malicious image can reach the parser through many apps, increasing the real-world attack surface. Public reports emphasize that exploitation observed so far has been selective and targeted, consistent with spyware-class operations.
Why this matters
This is one of several zero-days Apple has had to remediate in 2025. While not unusual in today’s threat landscape, such bugs are particularly dangerous because they enable code execution without obvious user interaction. Modern iPhones, iPads, and Macs rely on rich media processing throughout the system; any flaw in a central parser like ImageIO can become a powerful foothold for attackers to deploy surveillance payloads, exfiltrate data, or escalate privileges. U.S. cyber authorities have already highlighted the risk profile of this issue and urged rapid patching across fleets.
What you should do now
For individuals
- Update immediately: Install iOS/iPadOS 18.6.2 (or iPadOS 17.7.10 where applicable) and the latest macOS point release for your device. Enable Automatic Updates so you receive future fixes without delay.
- Be cautious with unsolicited images: Until fully patched, avoid opening unknown image attachments or clicking links that may render images in the browser or messaging apps.
- Check app permissions: Review camera, photos, and network permissions for apps that don’t need them.
For organizations
- Push the updates with urgency across managed iOS, iPadOS, and macOS fleets; track compliance and remediate stragglers. CISA guidance to U.S. civilian agencies includes a near-term patch deadline, underscoring urgency for enterprise environments.
- Harden media paths: Where possible, throttle automatic image previewing in email and messaging clients used in high-risk workflows.
- Threat hunt for exploitation artifacts: Monitor for abnormal ImageIO crashes, unexpected network egress from messaging or image-handling processes, and sudden spikes in preview/thumbnailing activity around the disclosure window (August 20–22, 2025). Use EDR telemetry and mobile management logs to pivot.
- Update detections: Incorporate the CVE into vulnerability management and ensure asset groups on hold for older OS major versions receive the corresponding point updates (e.g., Sonoma/Ventura).
Bottom line
CVE-2025-43300 is a classic example of a high-impact media-parsing bug: trivially delivered, broadly reachable, and now known to be exploited in the wild. Apple’s fixes are available today; applying them promptly is the most effective way to close this door. If your role or profile places you at higher risk—journalists, activists, executives, or government personnel—treat this as a priority patch and consider additional hardening until your entire device set is confirmed up to date
Download the apple update from: https://support.apple.com/en-us/100100
Please subscribe to the Newsletter so that you do not miss any critical update
