Apple is rolling out emergency updates addressing an “extremely sophisticated” attack vector likely used in targeted attacks.
The out-of-band updates, rolled out to iPhone, iPad and Mac users worldwide, address a single security issue tagged as serious by the Cupertino giant.
In other words, it’s an emergency release that users should prioritize.
Tracked as CVE-2025-43300, the security fault addressed in this round of updates is an out-of-bounds write weakness in ImageIO, a component Apple products use mainly for reading and writing image and video data.
An attacker can exploit the weakness by sending the target a malicious image file, leading to memory corruption and a window of opportunity to further the attack.
“Processing a malicious image file may result in memory corruption,” reads the advisory.
More importantly, it adds:
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”
Historically, such sophisticated attacks have involved spyware. The attackers, typically working for an authoritarian regime, target activists, dissidents, political rivals, human rights advocates, investigative journalists and other high-profile people. Apple, Google, and Meta, Facebook’s parent company, have been fighting the threat for years.
Even if you’re not a high-risk person, it’s always a good idea to stay up to date with the latest security patches – you never know when you accidentally trip a wire and become a target.
As of today, Apple users want to be running the following software versions:
iOS 18.6.2 and iPadOS 18.6.2 – on iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
iPadOS 17.7.10 – on iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation
macOS Sequoia 15.6.1 – on Macs running macOS Sequoia
macOS Sonoma 14.7.8 – on Macs running macOS Sonoma
macOS Ventura 13.7.8 – on Macs running macOS Ventura
For peace of mind, run a dedicated security solution on all your personal devices. And keep the trusty Lockdown Mode toggle handy if you have reason to believe hackers might be targeting you.
You may also want to read:
Patch Your iGear! iOS 18.6 Fixes a Security Bug Exploited in Google Chrome
Patch Your Web Browser! New Security Flaw in Chrome Exploited by Hackers
WhatsApp Patches Zero-Click Spyware Attack Vector on Android
tags
Filip has 15 years of experience in technology journalism. In recent years, he has turned his focus to cybersecurity in his role as Information Security Analyst at Bitdefender.
View all postsMay 16, 2025