Apple rushes out iOS update to patch dangerous image file exploit

来源 Cryptopolitan

Less than a week after releasing iOS 18.6.1, Apple has launched update 18.6.2, which could supposedly stop hackers from accessing devices through “malicious image files.”

The flaw, tracked as CVE-2025-43300, was identified inside Apple’s Image I/O framework, which handles the reading and writing of image files across its devices. According to the iPhone manufacturer, processing a maliciously crafted image could result in memory corruption and could allow an attacker to execute malicious code on the device.

Apple said the bug had been exploited by an “extremely sophisticated attack against specific targeted individuals.” The company fixed the problem with iOS 18.6.2 and parallel security patches for macOS Sequoia, Sonoma and Ventura, issued in an unscheduled update late Wednesday.

“For our customers’ protection, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available,” the company wrote on its official support page.

Affected devices and update availability

The iOS 18.6.2 update covers all iPhones released since 2018, beginning with the iPhone XS, XS Max, XR, and the second- and third-generation iPhone SE. The patch also extends to Apple’s latest devices, including the iPhone 16 series and iPhone 16e.

Supported iPad models include the iPad Pro 13-inch, iPad Pro 12.9-inch (2nd generation and later), iPad Pro 11-inch (1st generation and later), iPad Pro 10.5-inch, iPad Air (3rd generation and later), iPad (6th generation and later), and iPad mini (5th generation and later).

Apple issues urgent iOS update, iOS 18.6.2 update pinned critical for iPhone and iPads.
iOS new update notes. Source: Apple Support.

The update is also available for Apple’s Mac computers running the three most recent versions of macOS. The tech giant is asking users not to wait for the automatic rollout and instead apply the patch manually, as the auto update could take time reaching all devices.

How did update 18.6.1 make devices vulnerable?

According to several security analysts, the flaw is an out-of-bounds write vulnerability, a type of bug that allows attackers to access or manipulate sections of device memory that should normally be restricted.

Pieter Arntz, a former Microsoft consultant and researcher at cybersecurity firm Malwarebytes, explained in a blog post that the vulnerability could allow attackers to insert and run code in “inaccessible” parts of memory. 

“Such a flaw in a program allows it to read or write outside the bounds the program sets, enabling attackers to manipulate other parts of the memory allocated to more critical functions,” he wrote.

Arntz mentioned adversaries could exploit the bug by creating a malicious image file that corrupts memory as soon as the device processes it, even without user interaction. He compared the attack to so-called zero-click exploits, where spyware or malware is triggered simply by receiving or processing malicious content.

“Processing such a malicious image file would result in memory corruption,” he said. “Memory corruption issues can be manipulated to crash a process or run an attacker’s code.”

Apple has admitted it had received reports of the flaw being used in targeted attacks against certain individuals, but did not identify the victims.

Sean Wright, head of application security at Featurespace, believes the exploit was too complex to be deployed on a wide scale.

“Thankfully, the exploit does appear to be complex and likely only exploited in a very targeted attack, so most ordinary users are unlikely to become a victim,” Wright told Forbes. “But I would still highly recommend applying the fix as soon as possible to be on the safe side.”

If you're reading this, you’re already ahead. Stay there with our newsletter.

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
8月21日财经早餐:FED会议纪要揭示通胀风险、黄金大涨1%,标普500四连跌,蒸发1万亿美国美联储发表7月会议纪录显示,多数官员认为,通胀风险超过就业风险,数名官员对资产估值偏高感到忧虑。美国零售股及消费股业绩欠佳,加之投资者亦忧虑科企估值过高,科技股抛压加剧,进而拖累标普500指数连续四日下跌,蒸发约1万亿美元。美国三大指数普遍下跌,道指微升16点;标指跌0.24%,连续四日下跌;纳指挫0.67%;中国金龙指数微涨0.33%。英股创新高升1.08%,法、德股份别跌0.08%及0.6%。
作者  Insights
昨日 00: 40
美国美联储发表7月会议纪录显示,多数官员认为,通胀风险超过就业风险,数名官员对资产估值偏高感到忧虑。美国零售股及消费股业绩欠佳,加之投资者亦忧虑科企估值过高,科技股抛压加剧,进而拖累标普500指数连续四日下跌,蒸发约1万亿美元。美国三大指数普遍下跌,道指微升16点;标指跌0.24%,连续四日下跌;纳指挫0.67%;中国金龙指数微涨0.33%。英股创新高升1.08%,法、德股份别跌0.08%及0.6%。
placeholder
美股七巨头持续下挫!科技股崩盘风险加大?交易员抢购看跌期权交易员纷纷买入“灾难”看跌期权,防范美国科技股崩盘风险。有分析指出,担忧可能被夸大。
作者  Alison Ho
昨日 03: 48
交易员纷纷买入“灾难”看跌期权,防范美国科技股崩盘风险。有分析指出,担忧可能被夸大。
placeholder
Jackson Hole会议来袭!小心鲍威尔意外鸽派?黄金、比特币行情一触即发!机构对鲍威尔讲话看法分化,高盛倾向于鸽派立场,巴克莱、摩根大通则倾向于鹰派立场。
作者  Tony Chou
昨日 09: 24
机构对鲍威尔讲话看法分化,高盛倾向于鸽派立场,巴克莱、摩根大通则倾向于鹰派立场。
placeholder
台币汇率持续贬值创3个月新低!股市资金外流加剧波动受科技股资金外流影响,台币兑美元连续下跌,至5月份以来的最低水平。
作者  Alison Ho
10 小时前
受科技股资金外流影响,台币兑美元连续下跌,至5月份以来的最低水平。
placeholder
【今日市场前瞻】鲍威尔讲话重磅来袭!大行情一触即发!鲍威尔讲话倒数计时!全球市场情绪谨慎;美元指数反弹,黄金价格下挫;英伟达跌超1%,暂停生产H20晶片>>
作者  Alison Ho
3 小时前
鲍威尔讲话倒数计时!全球市场情绪谨慎;美元指数反弹,黄金价格下挫;英伟达跌超1%,暂停生产H20晶片>>
goTop
quote