Apple Rushes Critical Zero-Day Fix to Millions of Older iPhones After “Extremely Sophisticated” Attacks

# Apple Patches Critical Zero-Day Vulnerability in Older iPhones and iPads

Apple has released crucial security updates for older iPhone and iPad models, addressing a dangerous zero-day vulnerability that cybercriminals exploited in highly sophisticated targeted attacks.

## The Vulnerability Details

The security flaw, designated as CVE-2025-43300, affects Apple’s Image I/O framework—the system component responsible for processing image files. The vulnerability stems from an “out-of-bounds write” weakness, where malicious image files can cause the system to write data beyond allocated memory boundaries.

This type of attack can lead to:
– System crashes
– Data corruption
– Remote code execution by attackers

Apple’s security team discovered the vulnerability and confirmed that threat actors had already exploited it in real-world attacks targeting specific individuals.

## Affected Devices

The vulnerability impacts a wide range of older Apple devices, including:

**iPhones:**
– iPhone 6s (all variants)
– iPhone 7 (all variants)
– iPhone SE (1st generation)
– iPhone 8 and 8 Plus
– iPhone X

**iPads:**
– iPad Air 2
– iPad mini (4th generation)
– iPad 5th generation
– iPad Pro 9.7-inch and 12.9-inch (1st generation)
– iPod touch (7th generation)

## The Fix

Apple has addressed the vulnerability in iOS 15.8.5/16.7.12 and iPadOS 15.8.5/16.7.12 by implementing improved bounds checking mechanisms. The company had previously patched this same flaw in newer devices running iOS 18.6.2 and other current operating systems in August.

## Part of a Larger Attack Campaign

Security researchers revealed that this Apple vulnerability was chained with a separate WhatsApp zero-day flaw (CVE-2025-55177) in coordinated attacks. WhatsApp has since patched its vulnerability and warned affected users about the advanced spyware campaign targeting their devices.

Samsung also addressed a related vulnerability in its Android devices that was exploited alongside the WhatsApp flaw.

## Apple’s 2025 Zero-Day Track Record

This latest patch marks the sixth zero-day vulnerability that Apple has fixed in 2025 after confirming active exploitation:
– January: CVE-2025-24085
– February: CVE-2025-24200
– March: CVE-2025-24201
– April: CVE-2025-31200 and CVE-2025-31201
– August: CVE-2025-43300

## Recommendation

Users with affected older Apple devices should immediately install the available security updates to protect against potential attacks. The sophisticated nature of these exploits underscores the critical importance of maintaining current security patches, even on older hardware.

Share This Article