Apple has issued emergency security updates to fix a dangerous vulnerability that cybercriminals are actively exploiting in sophisticated attacks against specific individuals.
## The Threat
The security flaw, designated CVE-2025-43300, is an out-of-bounds write vulnerability located in Apple’s ImageIO framework. This component handles image processing across Apple devices. When a device processes a specially crafted malicious image, the vulnerability can corrupt system memory, potentially allowing attackers to take control of the device.
Apple confirmed that this zero-day exploit has been used in “extremely sophisticated attacks” targeting specific individuals, though the company has not revealed who was behind the attacks or identified the victims.
## Affected Systems and Updates
The vulnerability impacts multiple Apple platforms, and users should immediately install the following security updates:
**iOS and iPadOS Devices:**
– iOS 18.6.2 and iPadOS 18.6.2 for newer devices (iPhone XS and later, recent iPad models)
– iPadOS 17.7.10 for older iPad models
**Mac Computers:**
– macOS Ventura 13.7.8
– macOS Sonoma 14.7.8
– macOS Sequoia 15.6.1
Apple resolved the issue by implementing improved bounds checking to prevent memory corruption attacks.
## Growing Zero-Day Threat
This latest patch brings Apple’s total zero-day fixes to seven since the beginning of 2025, highlighting the increasing threat landscape facing Apple users. The company has been actively addressing vulnerabilities that criminals exploit before security researchers can identify and patch them.
Additionally, Apple recently patched a Safari vulnerability (CVE-2025-6558) that Google had previously reported as being exploited in Chrome browser attacks.
## Immediate Action Required
Security experts strongly recommend that all Apple device users install these updates immediately. Given the active exploitation and targeted nature of these attacks, delaying the update could leave devices vulnerable to sophisticated cybercriminals.
Users can check for updates through their device settings and should enable automatic updates to ensure future security patches install promptly.
