ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Apple Releases Patch for Likely Exploited Zero

mediumVulnerabilityimportance 35CVE-2025-43300

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43300
Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O

CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions.

10.022% KEV PoC
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion)
Full article332 words · extracted from infosecurity-magazine.com · click to collapse

In a series of updates for its iOS, iPadOS, and macOS operating systems, Apple released a patch for a previously unknown vulnerability that has likely been exploited in highly targeted attacks.

The vulnerability, tracked as CVE-2025-43300, is an out-of-bounds write vulnerability in the Image I/O framework, Apple’s built-in framework which allows  developers to read, write and manipulate image data efficiently.

It affects macOS Ventura before version 13.7, macOS Sonoma before version 14.7, macOS Sequoia before version 15.6, iOS before 18.6 and iPadOS before 17.7 and 18.6.

When the vulnerability is exploited, processing a malicious image file may result in memory corruption.

Apple did not provide a severity score for this vulnerability.

However, the company stated in an August 20 security advisory that it was "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."

The updates to patched versions, rolled out on August 20, included the following systems:

  • macOS Ventura 13.7.8
  • macOS Sonoma 14.7.8
  • macOS Sequoia 15.6.1
  • iOS 18.6.2
  • iPadOS 17.7.10
  • iPadOS 18.6.2

Open Door for ‘Zero-Click’ Spyware Attacks

Experts reacting to these updates urged Apple users to quickly install the patched versions, even though known exploitation seemed to be targeted and highly targeted.

Sylvain Cortes, VP of strategy at Hackuity, noted that the vulnerability potentially “opens the door to so-called ‘zero-click’ attacks, where a simple malicious message could let attackers run code without any action from the victim.”

“Previous exploits of this nature have been used to target government officials, journalists and other high-value individuals,” he added.

Adam Boynton, a senior security strategy manager at Jamf, expressed similar concerns.

“While Apple has not confirmed whether this specific flaw was linked to spyware, similar vulnerabilities in Image I/O and WebKit have previously been used in Pegasus campaigns,” he stated.

“Even though the exploitation appears targeted, we recommend that all users update to iOS 18.6.2 immediately, particularly those in industries most at risk of spyware attacks.”

Photo credits: nikkimeel / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-patch-likely-exploited-zero/