logo

Apple Patches Zero-Day Flaw Used in 'Sophisticated' Attack

ID: 0fbcc4f3-efa7-50a5-aab3-ffbfcb1d5567

STIX ID: report--0fbcc4f3-efa7-50a5-aab3-ffbfcb1d5567

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-08-22

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework that could cause memory corruption when processing a malicious image and was reportedly exploited in an "extremely sophisticated" targeted attack against specific individuals; the flaw affects iOS, iPadOS, and macOS and was fixed via improved bounds checking. Apple released few technical details, and the report contextualizes this fix within a series of zero-day disclosures and past exploitation by commercial spyware vendors such as Paragon Solutions and NSO Group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.