Apple patches zero-day CVE-2025-43300: malicious images could run code

mayanicks0x · x · 2026-09-12

Apple has issued emergency updates fixing a new zero-day vulnerability, CVE-2025-43300, in the ImageIO framework. Crafted malicious image files could trigger arbitrary code execution. Update to iOS 18.6.2 or macOS 15.6.1 immediately and avoid opening untrusted images until patched.

Original post →

More from Safety

Safety channel →