ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple backports fix for actively exploited CVE-2025

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-43300CVE-2025-55177

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43300
Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O

CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions.

10.022% KEV PoC
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion)
CVE-2025-55177
Incorrect Authorization in WhatsApp Linked-Device Sync Used in Targeted Spyware Attacks

CVE-2025-55177 is an incorrect authorization flaw (CWE-863) in how WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac validate linked device synchronization messages, allowing an unrelated user to trigger processing of content from an arbitrary URL on a target's device. An attacker can reach a vulnerable client through the messaging channel without normal authorization checks, causing the app to fetch or process attacker-chosen content. On its own the flaw carries only partial confidentiality and integrity impact (CVSS 5.4), but Meta assesses it was chained with an Apple OS vulnerability (CVE-2025-43300) in a sophisticated attack against specific, targeted users. Users running WhatsApp for iOS before 2.25.21.73, WhatsApp Business for iOS before 2.25.21.78, or WhatsApp for Mac before 2.25.21.78 are affected. The flaw was added to CISA's KEV catalog on 2025-09-02 amid reports of highly targeted zero-day attacks, though no public proof-of-concept is known and use in ransomware campaigns has not been reported.

Do: Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Also apply Apple's backported OS fix for CVE-2025-43300, since the two flaws were combined in the observed attack chain. Review and re-link WhatsApp companion devices if compromise is suspected; federal agencies must follow BOD 22-01 required-action deadlines per the KEV listing.

5.44% KEV
  • Meta Platforms WhatsApp for iOS all versions prior to 2.25.21.73
  • Meta Platforms WhatsApp Business for iOS all versions prior to 2.25.21.78
  • Meta Platforms WhatsApp for Mac all versions prior to 2.25.21.78
masshundreds of millions of users (WhatsApp's multi-billion user base includes a very large iOS/macOS install base)
Full article352 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 17, 2025

Apple announced it has backported patches for a recently addressed actively exploited vulnerability tracked as CVE-2025-43300.

Apple has backported security patches released to address an actively exploited vulnerability tracked as CVE-2025-43300.

In August 2025, Apple addressed the actively exploited zero-day CVE-2025-43300 in iOS, iPadOS, and macOS. The vulnerability is zero-day out-of-bounds write issue that resides in the ImageIO framework, an attacker could exploit it to cause memory corruption when processing a malicious image.

“Processing a malicious image file may result in memory corruption.” reads the advisory published by the tech giant. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

The company fixed the problem with improved bounds checking. Apple released the following updates to fix the issue:

  • iOS 18.6.2 and iPadOS 18.6.2 – iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
  • iPadOS 17.7.10 – iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation
  • macOS Ventura 13.7.8 – Mac systems running macOS Ventura
  • macOS Sonoma 14.7.8 – Macs systems running macOS Sonoma
  • macOS Sequoia 15.6.1 – Macs systems running macOS Sequoia

As usual, the company did not share technical details about the attacks exploiting this vulnerability.

WhatsApp recently confirmed attackers chained CVE-2025-55177 with CVE-2025-43300 in spyware campaigns targeting fewer than 200 people. Apple patched the flaws in recent iOS, iPadOS, and macOS updates, including older versions.

Below are the updates released by Apple to address the issue:

  • iOS 16.7.12 and iPadOS 16.7.12 – iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
  • iOS 15.8.5 and iPadOS 15.8.5 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2025-43300)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182283/security/apple-backports-fix-for-actively-exploited-cve-2025-43300.html