Skip to content

Defense Digests

Apple Confirms Exploited Zero Day Vulnerability

d3

Table of content

Vulnerability: CVE-2025-43300 

Severity Level: 8.8 (High) 

Updated as of 8.22.2025

Executive Summary 

Apple has issued an urgent security patch to address a critical zero-day vulnerability (CVE-2025-43300) in its ImageIO framework. This vulnerability could allow attackers to run malicious code on a device simply by sending a harmful image. Users of iPhones, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, iPad mini 5th generation and later, and Macs are advised to install the updates immediately. 

Details 

  • The bug lies within ImageIO, the system Apple uses to process image files across iOS, iPadOS, and macOS. 
  • The problem comes from an out-of-bounds memory issue that can be triggered by specially corrupted images. 
  • This will allow the attackers to force the system to write data outside of its normal memory space. This memory error can then be turned into code execution, meaning the attackers could run commands of their choice on the device.  
  • Apple confirmed that this bug has been used in targeted attacks, most likely against specific highvalue individuals. 

Impact 

  • Attackers can get control of a device through remote code execution (delivery of a malicious image file). 
  • The vulnerability affects a wide range of Apple devices, including recent iPads, iPhones, and macOS systems. 

Mitigation Strategies 

  1. Apply the latest patches released by Apple immediately (install iOS 18.6.2, iPadOS 18.6.2, and macOS Sequoia 15.6.1, Sonoma 14.7.8, Ventura 13.7.8). 
  1. Enable automatic update to ensure future patches are installed quickly. 
  1. Avoid opening images or attachments from untrusted sources. 
     

Sources 

Contributing Authors 
Benjamin Kalombo – Cybersecurity Analyst II, Dataprise
Pat Scarangelli – Cybersecurity Analyst I, Dataprise
Jason Law – Cybersecurity Analyst I, Dataprise

Recent Tweets

INSIGHTS

Learn about the latest threats and vulnerabilities with our D3 alerts.

Subscribe to get real-time notifications when a new Dataprise Defense Digest is published.