CISA warns of Apple zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41061 | Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11. Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds. | 7.8 | 4% | KEV |
| massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched) | |
| CVE-2023-41064 | ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs. Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices. | 7.8 | 45% | KEV |
| masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion) | |
| CVE-2025-43300 | Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed. Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions. | 10.0 | 22% | KEV PoC |
| mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion) |
Full article464 words · extracted from therecord.media · click to collapse
A recently disclosed vulnerability affecting Apple products has prompted an order for government organizations to patch the bug. The Cybersecurity and Infrastructure Security Agency (CISA) gave civilian federal agencies until September 11 to implement a fix for CVE-2025-43300 — a vulnerability affecting popular brands of Apple phones, iPads and Macbooks. Apple said on Wednesday that it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.” CISA added it to the Known Exploited Vulnerability catalog on Thursday. CISA officials gave the vulnerability a severity rating of 8.8 out of 10. Apple did not respond to requests for clarification about how it is being used. Qualys security research manager Mayuresh Dani explained that the vulnerability affects Apple's ImageIO framework, a core system component responsible for processing various image formats across iOS, iPadOS, and macOS. “This is a zero-click exploit that requires no user interaction, and can be triggered simply by processing a maliciously crafted image file, which could be delivered through various channels including messages, emails, or web content,” Dani said. At the Black Hat security conference two weeks ago, Censys security researcher Aidan Holland told Recorded Future News that threat actors have had to switch to malicious images as their way into Apple devices because the company blocks links from unknown senders. One way around it is to get people to click and download an image, he explained. The tech giant has released patches for multiple zero-day vulnerabilities in 2025 — many of which Apple and other security companies attribute to sophisticated spyware vendors. Several of the companies have faced international sanctions and lawsuits over their specific targeting of Apple systems. Many of the vulnerabilities found are sold to governments that have used them to target political rivals, dissidents and others. Dani noted that as recently as 2023, the BLASTPASS exploit chain – CVE-2023-41064 and CVE-2023-41061 – also targeted ImageIO and was used to deploy the NSO Group’s Pegasus spyware. Satnam Narang, senior staff research engineer at Tenable, said Apple rarely used language like “an extremely sophisticated attack against specific targeted individuals” in security advisories. “While the impact to the wider populace is smaller because the attackers exploiting CVE-2025-43300 had a narrow, targeted focus, Apple wants the public to pay attention to the threat and take immediate action,” Narang said. “While the possibility of the average user being a target is low, it’s never zero.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warns-of-apple-zero-day