
Apple released emergency security updates for iPhones, iPads and Macs after disclosing a zero-day vulnerability, CVE-2025-43300, in the ImageIO framework that processes image files. The flaw allows attackers to take full control of a device by sending a single specially crafted image, and does not require the victim to click or tap the file. The company said it is aware of "extremely sophisticated" attacks exploiting the weakness against a small number of specific targets. Researchers categorised the bug as a remote-code-execution issue caused by an out-of-bounds write, which Apple addressed through improved bounds checking. The fixes are bundled in iOS 18.6.2, iPadOS 18.6.2 and macOS Sequoia 15.6.1, with parallel patches for earlier operating-system branches. Apple urged users to install the updates immediately to block potential compromise, while security analysts warned that the underlying technique could spread quickly once technical details become public.
PSA: Be Sure to Update iOS 18.6.2, iPadOS 18.6.2, and macOS Sequoia 15.6.1, As They Fix an Actively Exploited Vulnerability #applenews https://t.co/DqC1YrJrcv https://t.co/1DAXs0J0Sw
🚨 APPLE ISSUES EMERGENCY PATCH FOR ZERO-DAY IMAGE EXPLOIT TARGETING IPHONES & MACS ⚠️ Apple confirms active exploitation of CVE-2025-43300 — a zero-day flaw in Image I/O. 🖼️ One malicious image = full device compromise. No clicks needed. 📲 iOS 18.6.2, macOS Sequoia 15.6.1, https://t.co/xbKgjuHiV4
Les iPhone ont toujours un problème de chauffe l’été : il est temps qu’Apple le règle https://t.co/QOS6yNXuME


