{"id":15142,"date":"2025-08-22T01:35:07","date_gmt":"2025-08-22T01:35:07","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/15142\/"},"modified":"2025-08-22T01:35:07","modified_gmt":"2025-08-22T01:35:07","slug":"apple-issues-emergency-update-to-fix-zero-day-flaw-in-imageio-framework","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/15142\/","title":{"rendered":"Apple issues emergency update to fix zero-day flaw in ImageIO framework"},"content":{"rendered":"<p>Apple Inc. has released an emergency security update to address a zero-day vulnerability in its ImageIO framework that has been actively exploited in the wild.<\/p>\n<p>A zero-day is a previously unknown software vulnerability that is discovered by attackers before the developer has created a fix. The ImageIO framework is a core component of Apple\u2019s operating systems responsible for handling various image file formats.<\/p>\n<p>The zero-day in this case, tracked as CVE-2025-43300, is <a href=\"https:\/\/support.apple.com\/en-us\/124925\" rel=\"nofollow noopener\" target=\"_blank\">described by Apple<\/a> as allowing for the processing of a malicious image file that may result in memory corruption. Apple confirmed it is aware of reports that the vulnerability may have been exploited in targeted attacks before the patch was released, though the company did not provide details about the scope or attribution.<\/p>\n<p>The patches, released on Aug. 20, cover iOS, iPadOS and macOS. The fix is included in iOS 18.6.2 and iPadOS 18.6.2 for current devices, iPadOS 17.7.10 for older models and macOS Sequoia 15.6.1, Sonoma 14.7.8 and Ventura 13.7.8.<\/p>\n<p>Users are advised to update their devices immediately to the latest versions. On iPhones and iPads, updates can be installed under Settings &gt; General &gt; Software Update, while Mac users can apply them through System Settings &gt; General &gt; Software Update.<\/p>\n<p>Discussing the vulnerability, Adam Boynton, senior security strategy manager at Apple device management company <a href=\"https:\/\/www.jamf.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Jamf Holding Corp.<\/a>, told SiliconANGLE via email that \u201cApple has indicated that this vulnerability has been exploited in sophisticated, targeted attacks, which typically focus on individuals with highly valued access or contacts, such as journalists, lawyers, activists and government officials.\u201d<\/p>\n<p>\u201cWhile Apple has not confirmed whether this specific flaw was linked to spyware, similar vulnerabilities in ImageIO and WebKit have previously been used in Pegasus campaigns,\u201d Boynton added. \u201cEven though the exploitation appears targeted, we recommend that all users update to iOS 18.6.2 immediately, particularly those in industries most at risk of spyware attacks.\u201d<\/p>\n<p>Satnam Narang, senior staff research engineer at exposure management company <a href=\"https:\/\/www.tenable.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Tenable Holdings Inc.<\/a>, commented that \u201ctraditionally, Apple has limited the amount of detail it shares about in-the-wild exploitation of zero-days across Apple products. However, they rarely use the language of \u2018an extremely sophisticated attack against specific targeted individuals.&#8217;\u201d<\/p>\n<p>\u201cBased on my assessment, Apple started using this language in 2025 for other CVEs, including CVE-2025-24201, CVE-2025-24200, CVE-2025-31200, CVE-2025-43200, and CVE-2025-43300,\u201d added Narang. \u201cThis language suggests that Apple is being purposeful in its external communication.\u201d<\/p>\n<p>Image: SiliconANGLE\/Reve<\/p>\n<p>Support our mission to keep content open and free by engaging with theCUBE community. <strong>Join theCUBE\u2019s Alumni Trust Network<\/strong>, where technology leaders connect, share intelligence and create opportunities.<\/p>\n<ul>\n<li class=\"text-xl md:text-2xl text-gray-300 mb-8 max-w-4xl mx-auto\" data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>15M+ viewers of theCUBE videos<\/strong>, powering conversations across AI, cloud, cybersecurity and more<\/li>\n<li data-replit-metadata=\"client\/src\/pages\/Home.tsx:123:12\" data-component-name=\"p\"><strong>11.4k+ theCUBE alumni<\/strong> \u2014 Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.<\/li>\n<\/ul>\n<p><strong>About SiliconANGLE Media<\/strong><\/p>\n<p>SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fsiliconangle.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=SiliconANGLE&amp;index=9&amp;md5=646b1b564e2259100a2b8638aab0a552\" rel=\"nofollow noopener\" target=\"_blank\">SiliconANGLE<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecube.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Network&amp;index=10&amp;md5=7de2a85f95ab4a4a495cede20b8cb1da\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Network<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fthecuberesearch.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+Research&amp;index=11&amp;md5=7bb33676722925eb57d588ec343e4f6f\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE Research<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.cube365.net%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=CUBE365&amp;index=12&amp;md5=d310fb35919714e66ad8d42c9c0c1bc6\" rel=\"nofollow noopener\" target=\"_blank\">CUBE365<\/a>, <a href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.thecubeai.com%2F&amp;esheet=54119777&amp;newsitemid=20240910506833&amp;lan=en-US&amp;anchor=theCUBE+AI&amp;index=13&amp;md5=b8b98472f8071b23ebb10ab9a8dd0683\" rel=\"nofollow noopener\" target=\"_blank\">theCUBE AI<\/a> and theCUBE SuperStudios \u2014 with flagship locations in Silicon Valley and the New York Stock Exchange \u2014 SiliconANGLE Media operates at the intersection of media, technology and AI.<\/p>\n<p>Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.<\/p>\n","protected":false},"excerpt":{"rendered":"Apple Inc. has released an emergency security update to address a zero-day vulnerability in its ImageIO framework that&hellip;\n","protected":false},"author":2,"featured_media":15143,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[74],"tags":[13776,2081,18,19,17,2082,82],"class_list":{"0":"post-15142","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-apple-issues-emergency-update-to-fix-zero-day-flaw-in-imageio-framework","9":"tag-duncan-riley","10":"tag-eire","11":"tag-ie","12":"tag-ireland","13":"tag-siliconangle","14":"tag-technology"},"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/15142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=15142"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/15142\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/15143"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=15142"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=15142"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=15142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}