Particle.news

Download on the App Store

Apple Patches Zero-Click Image Exploit Allowing Device Takeover on iPhone, iPad and Mac

U.S. cyber officials set a September 11 deadline for government systems, underscoring heightened risk for high-value users such as cryptocurrency holders.

Hackers Could Take Over Apple Devices Via Malicious Images – Patch Now!
Apple issues emergency patches for zero‑click exploit that may enable crypto wallet theft

Overview

  • Apple fixed CVE-2025-43300, an Image I/O out-of-bounds write that lets a crafted image compromise a device without any user action.
  • Updates released on August 20 address the flaw in iOS 18.6.2, iPadOS 18.6.2, and macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by September 11, 2025.
  • Apple says the bug was used in an extremely sophisticated attack against specific targeted individuals, with no attribution disclosed.
  • Security experts warn crypto users to patch immediately and, if compromise is suspected, move funds to new wallets with keys generated on a clean or hardware wallet device.