Apple Patches Zero-Day Flaw Used in 'Sophisticated' Attack
ID: 0fbcc4f3-efa7-50a5-aab3-ffbfcb1d5567
STIX ID: report--0fbcc4f3-efa7-50a5-aab3-ffbfcb1d5567
Feed Name: Dark Reading
Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework that could cause memory corruption when processing a malicious image and was reportedly exploited in an "extremely sophisticated" targeted attack against specific individuals; the flaw affects iOS, iPadOS, and macOS and was fixed via improved bounds checking. Apple released few technical details, and the report contextualizes this fix within a series of zero-day disclosures and past exploitation by commercial spyware vendors such as Paragon Solutions and NSO Group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
