The National Computer Emergency Response Team (NCERT) has issued a warning about a serious security flaw found in Apple’s ImageIO framework, identified as CVE-2025-43300. The zero-day vulnerability allows hackers to overwrite memory when a device processes a malicious image file, potentially giving them full control over affected iPhones, iPads, and Macs.

According to NCERT, the flaw is being actively exploited in targeted attacks, making it a high-risk threat for both individuals and organizations using Apple[1] devices. If successfully exploited, the bug can cause memory corruption, allow unauthorized access, compromise system integrity, and expose sensitive data.

Attackers can trigger the vulnerability remotely, often by tricking users into opening a maliciously crafted image file. No special permissions are required for the attack to work. Apple has already released urgent security updates to fix the issue and protect users.

The vulnerability was first discovered in iOS 17.4 and continues to affect multiple later versions of Apple’s operating systems. NCERT has advised users to immediately update to iOS and iPadOS 18.6.2 or later, and macOS Sequoia 15.6.1, Ventura 13.7.8, or Sonoma 14.7.8.

For those unable to update right away, NCERT recommends avoiding image files from unknown sources, disabling automatic image rendering, and monitoring system logs for unusual crashes or memory-related issues.

Although no indicators of compromise (IoCs) have been released yet, NCERT urges organizations to stay alert for suspicious image file activity or unexplained device instability. It also advises enabling automatic updates, using mobile device management (MDM) tools to enforce patching, and strengthening endpoint monitoring to detect exploit attempts involving image files.

The agency stressed that timely updates are critical. Users are strongly urged to install Apple’s latest security patches without delay to prevent full device compromise and protect both personal and enterprise data from ongoing exploitation campaigns.

References

  1. ^ Apple Mobiles Price in Pakistan (propakistani.pk)

By admin