Apple on Monday released security updates for flaws in macOS, iPhone and iPad software, warning of bugs that allow malicious code simply by opening a tampered image, video or web page.
See also: Apple: Will it raise prices on new iPhones?

The new iOS 18.5 update, which comes with corresponding patches for iPadOS, addresses critical vulnerabilities in AppleJPEG and CoreMedia. Apple warns that attackers can craft malicious media files that could allow arbitrary code to be executed with the privileges of the target app.
The company also documented serious file parsing vulnerabilities that were patched in CoreAudio, CoreGraphics, and ImageIO. These vulnerabilities could lead to application crashes or data leakage when malicious content is opened.
The iOS 18.5 update also patches at least 9 documented vulnerabilities in WebKit, some of which are so severe that they could allow code execution or crash the Safari via a malicious website.
The company also fixed a serious bug in FaceTime related to the mute button, which allowed audio to be transmitted even after the microphone was muted.
See also: Apple's 'AirBorne' flaws lead to zero-click AirPlay attacks
At the operating level, Apple said that iOS 18.5 strengthens kernel protection against two memory corruption issues and fixes a bug in the libexpat library (CVE-2024-8176), which affects a wide range of software.

Other important fixes include:
- A Baseband vulnerability (CVE-2025-31214) that allows attackers with privileged network access to intercept data on the new iPhone 16e series.
- An elevation of privilege bug in mDNSResponder (CVE-2025-31222).
- A bug in the Notes app that could expose data even when the iPhone screen is locked.
- Security vulnerabilities in FrontBoard, iCloud Document Sharing, and email address management in the Mail app.
Apple said that, so far, there is no evidence that any of the fixed flaws have been actively exploited by attackers.
The iOS 18.5 update is available for iPhone XS and later models, while the corresponding version of iPadOS covers iPad Pro (models from 2018 and later), iPad Air 3rd generation, iPad 7th generation, iPad mini 5 and all newer models.
See also: Apple: Fixes two zero-days exploited in iPhone attacks
Apple also released major updates for macOS Sequoia, macOS Sonoma, macOS Ventura, as well as WatchOS, tvOS , and visionOS.
Source: securityweek
