Apple has shipped emergency updates to fix an actively exploited zero-day in its ImageIO framework, warning that the flaw has already been abused in targeted attacks. Logged as CVE-2025-43300, the bug is an out-of-bounds write issue in ImageIO, the component apps rely on to read and write standard image formats. Apple warned that the flaw could let miscreants hijack devices with a booby-trapped image – and for some iDevice users, it sounds like the damage has already been done. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals," Cupertino said. Apple went on to explain that "processing a malicious image file may result in memory corruption," but didn't say what that could lead to. Typically, though, these types of flaws allow stealthy attackers to spy on users and steal sensitive data. The company credits its own security team with the find and says it has tightened bounds checking to close the hole. Fixes landed on August 20 for iOS and iPadOS 18.6.2, macOS Sequoia 15.6.1, and the still-supported Sonoma 14.7.8 and Ventura 13.7.8, with a parallel update for older iPads on iPadOS 17.7.10. As usual, Apple is keeping the juicy details under wraps. There's no attribution, no list of targets, and no technical write-up beyond the basics. However, the phrasing in Apple's release notes suggests the flaw has been abused by a sophisticated hacking group, potentially a spyware developer, rather ...
Apple rushes out fix for active zero-day in iOS and macOS
The Register
·Carly Page
·Published Aug 21, 2025
·Updated
Affected Software
1 affected component
Apple ImageIO
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Apple's ImageIO framework that has been actively exploited.
2
What security implications are discussed in the article?
The article highlights that the zero-day vulnerability could allow attackers to execute targeted attacks by exploiting an out-of-bounds write issue.
3
What products or software are affected by the vulnerability?
The affected software includes Apple's ImageIO framework on both iOS and macOS.
4
What steps has Apple taken in response to the security threat?
Apple has released emergency updates to fix the vulnerability and protect users.
5
What is the identification number assigned to the vulnerability?
The vulnerability is logged as CVE-2025-43300.