logo

CISA warns of Apple zero-day used in targeted cyberattacks

ID: f19ff348-7327-5589-81b3-10aa9cf35b78

STIX ID: report--f19ff348-7327-5589-81b3-10aa9cf35b78

Feed Name: The Record from Recorded Future News

Threat Score
82/100

Date Published: 2025-08-22

Date Updated: 2026-05-01

...
...

A zero-click vulnerability in Apple’s ImageIO (CVE-2025-43300, severity 8.8) is being exploited in the wild to target specific individuals; CISA issued a directive requiring federal agencies to patch and Apple released fixes. The exploit is triggered by processing maliciously crafted images delivered via messages, email, or web content and is associated with sophisticated spyware actors and prior ImageIO exploit chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.