Overview
- Apple fixed CVE-2025-43300, an Image I/O out-of-bounds write that lets a crafted image compromise a device without any user action.
- Updates released on August 20 address the flaw in iOS 18.6.2, iPadOS 18.6.2, and macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by September 11, 2025.
- Apple says the bug was used in an extremely sophisticated attack against specific targeted individuals, with no attribution disclosed.
- Security experts warn crypto users to patch immediately and, if compromise is suspected, move funds to new wallets with keys generated on a clean or hardware wallet device.