• News/
  • https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-ipads/

Apple backports zero-day patches to older iPhones and iPads

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 16, 2025
·
Updated

​Apple has released security updates to backport patches released last month to older iPhones and iPads, addressing a zero-day bug that was exploited in "extremely sophisticated" attacks. This security flaw is the same one Apple has patched for devices running iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, and macOS (Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8) on August 20. Tracked as CVE-2025-43300, this vulnerability was discovered by Apple security researchers and is caused by an out-of-bounds write weakness in the Image I/O framework, which enables apps to read and write image file formats. An out-of-bounds write occurs when attackers supply maliciously crafted input to a program that causes it to write data outside the allocated memory buffer, potentially triggering crashes, corrupting data, or even allowing remote code execution. Apple has now addressed this zero-day flaw in iOS 15.8.5 / 16.7.12, as well as iPadOS 15.8.5 / 16.7.12, with improved bounds checks. "Processing a malicious image file may result in memory corruption. An out-of-bounds write issue was addressed with improved bounds checking," the company said in Monday advisories. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals." The list of devices impacted by this vulnerability is quite extensive, with the bug affecting a wide range of older models, including: In late August, WhatsApp patched a zero-click vuln...

Read full article

Affected Software

10 affected components
Apple iOS=15.8.5
Apple iOS=16.7.12
Apple iPadOS=15.8.5
Apple iPadOS=16.7.12
Apple iOS=18.6.2
Apple iPadOS=18.6.2
Apple iPadOS=17.7.10
Apple macOS=Sequoia 15.6.1
Apple macOS=Sonoma 14.7.8
Apple macOS=Ventura 13.7.8

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Apple's release of security updates to patch a zero-day vulnerability in older iPhones and iPads.

2

What zero-day flaw is addressed in the article?

The article highlights a zero-day bug that was exploited in highly sophisticated attacks, prompting the need for backported patches.

3

Which Apple products are affected by the security updates?

Affected products include older iPhones and iPads running iOS and iPadOS versions, along with certain macOS versions.

4

What versions of iOS and iPadOS received the backported patches?

The patches were backported to iOS and iPadOS versions 15.8.5, 16.7.12, and 18.6.2.

5

Why is it important to update to the latest software versions mentioned in this article?

Updating to the latest software versions is crucial to protect devices from exploitation of the known zero-day vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203