Apple rushes out iOS update to patch dangerous image file exploit

來源 Cryptopolitan

Less than a week after releasing iOS 18.6.1, Apple has launched update 18.6.2, which could supposedly stop hackers from accessing devices through “malicious image files.”

The flaw, tracked as CVE-2025-43300, was identified inside Apple’s Image I/O framework, which handles the reading and writing of image files across its devices. According to the iPhone manufacturer, processing a maliciously crafted image could result in memory corruption and could allow an attacker to execute malicious code on the device.

Apple said the bug had been exploited by an “extremely sophisticated attack against specific targeted individuals.” The company fixed the problem with iOS 18.6.2 and parallel security patches for macOS Sequoia, Sonoma and Ventura, issued in an unscheduled update late Wednesday.

“For our customers’ protection, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available,” the company wrote on its official support page.

Affected devices and update availability

The iOS 18.6.2 update covers all iPhones released since 2018, beginning with the iPhone XS, XS Max, XR, and the second- and third-generation iPhone SE. The patch also extends to Apple’s latest devices, including the iPhone 16 series and iPhone 16e.

Supported iPad models include the iPad Pro 13-inch, iPad Pro 12.9-inch (2nd generation and later), iPad Pro 11-inch (1st generation and later), iPad Pro 10.5-inch, iPad Air (3rd generation and later), iPad (6th generation and later), and iPad mini (5th generation and later).

Apple issues urgent iOS update, iOS 18.6.2 update pinned critical for iPhone and iPads.
iOS new update notes. Source: Apple Support.

The update is also available for Apple’s Mac computers running the three most recent versions of macOS. The tech giant is asking users not to wait for the automatic rollout and instead apply the patch manually, as the auto update could take time reaching all devices.

How did update 18.6.1 make devices vulnerable?

According to several security analysts, the flaw is an out-of-bounds write vulnerability, a type of bug that allows attackers to access or manipulate sections of device memory that should normally be restricted.

Pieter Arntz, a former Microsoft consultant and researcher at cybersecurity firm Malwarebytes, explained in a blog post that the vulnerability could allow attackers to insert and run code in “inaccessible” parts of memory. 

“Such a flaw in a program allows it to read or write outside the bounds the program sets, enabling attackers to manipulate other parts of the memory allocated to more critical functions,” he wrote.

Arntz mentioned adversaries could exploit the bug by creating a malicious image file that corrupts memory as soon as the device processes it, even without user interaction. He compared the attack to so-called zero-click exploits, where spyware or malware is triggered simply by receiving or processing malicious content.

“Processing such a malicious image file would result in memory corruption,” he said. “Memory corruption issues can be manipulated to crash a process or run an attacker’s code.”

Apple has admitted it had received reports of the flaw being used in targeted attacks against certain individuals, but did not identify the victims.

Sean Wright, head of application security at Featurespace, believes the exploit was too complex to be deployed on a wide scale.

“Thankfully, the exploit does appear to be complex and likely only exploited in a very targeted attack, so most ordinary users are unlikely to become a victim,” Wright told Forbes. “But I would still highly recommend applying the fix as soon as possible to be on the safe side.”

If you're reading this, you’re already ahead. Stay there with our newsletter.

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
輝達股價暴跌4%市值蒸發1550億,納指受拖累下跌1.5%,市場靜待財報與B30A晶片動向當地時間週二(8月19日),美國納斯達克綜合指數大幅下挫,大型科技股幾乎全線下跌,科技股巨頭輝達收盤跌約4%至每股單價175.64美元,市值蒸發超過1550億美元,這也是今年4月份以來的單日最大跌幅。其他科技股甲骨文、超威半導體(AMD)跌幅超過5%,博通、台積電跌超3%。科技股巨頭集體下滑,拖累納指跌1.5%,「七巨頭」ETF也同步下跌。
作者  財富進化論
8 月 20 日 週三
當地時間週二(8月19日),美國納斯達克綜合指數大幅下挫,大型科技股幾乎全線下跌,科技股巨頭輝達收盤跌約4%至每股單價175.64美元,市值蒸發超過1550億美元,這也是今年4月份以來的單日最大跌幅。其他科技股甲骨文、超威半導體(AMD)跌幅超過5%,博通、台積電跌超3%。科技股巨頭集體下滑,拖累納指跌1.5%,「七巨頭」ETF也同步下跌。
placeholder
台積電股價暴跌後微彈,外資分析報告力撐股價,半導體產業前景是關鍵台積電(2330)於8月20日股價下探至1,140元,單日重挫45元,台股指數因此一度下滑至23,734.17點,月線失守,不過今天(21日)開盤後,台積電略微回升,最高上漲10元,現價1,145。
作者  財富進化論
昨日 10: 05
台積電(2330)於8月20日股價下探至1,140元,單日重挫45元,台股指數因此一度下滑至23,734.17點,月線失守,不過今天(21日)開盤後,台積電略微回升,最高上漲10元,現價1,145。
placeholder
美股七巨頭持續下挫!科技股崩盤風險加大?交易員搶購看跌期權交易員紛紛買進「災難」看跌期權,防範美國科技股崩盤風險。有分析指出,擔憂可能被誇大。
作者  Alison Ho
昨日 03: 45
交易員紛紛買進「災難」看跌期權,防範美國科技股崩盤風險。有分析指出,擔憂可能被誇大。
placeholder
警報拉滿!納指創5月來最慘週,AI神話遭暴擊,輝達財報成最後「救命稻草」?這波下跌並非由單一事件引發,核心推手正是撐起美股科技行情的 「七大巨頭」—— 連續兩日的集體下挫,讓整個板塊承壓。
作者  投資-槓把子
昨日 09: 52
這波下跌並非由單一事件引發,核心推手正是撐起美股科技行情的 「七大巨頭」—— 連續兩日的集體下挫,讓整個板塊承壓。
placeholder
「你的00878、高股息ETF也能被強制賣掉!」他欠稅擺爛沒繳,稅局出手:股票直接變現抵債「我的股票怎麼憑空沒了?」台中市的王先生最近遇上了件糟心事 —— 名下股票突然被強制變賣,找上門才知道,竟是自己忘了繳一筆欠稅,被法務部行政執行署盯上,股票成了 “抵債品”。
作者  投資-槓把子
11 小時前
「我的股票怎麼憑空沒了?」台中市的王先生最近遇上了件糟心事 —— 名下股票突然被強制變賣,找上門才知道,竟是自己忘了繳一筆欠稅,被法務部行政執行署盯上,股票成了 “抵債品”。
goTop
quote