Particle.news

Download on the App Store

Apple Releases iOS 18.6.2 to Fix ImageIO Exploit Reported in Targeted Attacks

Apple warns a malicious image can corrupt memory in ImageIO, potentially used against specific high‑value targets.

Overview

  • iOS 18.6.2 and iPadOS 18.6.2 are available over the air, and Apple recommends installing them immediately.
  • The patches address CVE-2025-43300, an out-of-bounds write in ImageIO that Apple fixed with improved bounds checking.
  • Apple also issued macOS Sequoia 15.6.1 and security updates for macOS 14.7.8, macOS 13.7.8, and iPadOS 17.7.10 to extend coverage to older software branches.
  • Apple credits its internal teams with discovering the flaw, and the updates do not introduce new user-facing features.
  • Unsupported older hardware did not receive patches, leaving those devices potentially exposed to the image-processing vulnerability.