Apple has released security updates (Backports) for a recently patched vulnerability that has been actively exploited online. The vulnerability was fixed in newer devices, but the new updates also cover older models.

This is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component, which could lead to memory corruption when processing a malicious image file.
"Apple is aware that this issue may have been used in a highly sophisticated attack against specific individuals," the company said.
WhatsApp acknowledged that a vulnerability in its messaging apps for iOS and macOS (CVE-2025-55177, CVSS score: 5.4) had been linked to CVE-2025-43300 as part of highly targeted spyware attacks that targeted fewer than 200 people.
See also: Samsung fixes serious zero-day vulnerability
Apple: Vulnerability fix
The problem was initially addressed by Apple late last month with the release of iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Ventura 13.7.8, macOS Sonoma 14.7.8, and macOS Sequoia 15.6.1.
With the new updates, however, it also covers the following older versions:
– iOS 16.7.12 and iPadOS 16.7.12 – iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
– iOS 15.8.5 and iPadOS 15.8.5 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
See also: GitLab patches vulnerabilities for DoS & SSRF attacks

The new updates have been released alongside iOS 26, iPadOS 26, iOS 18.7, iPadOS 18.7, macOS Tahoe 26, macOS Sequoia 15.7, macOS Sonoma 14.8, tvOS 26, visionOS 26, watchOS 26, Safari 26, and Xcode 26, which also address a number of other security vulnerabilities:
– CVE-2025-31255 – An authorization vulnerability in IOKit that could allow an application to access sensitive data
– CVE-2025-43362 – A vulnerability in LaunchServices that could allow an application to monitor keystrokes without user permission
– CVE-2025-43329 – A permissions vulnerability in Sandbox that could allow an application to escape its sandbox
– CVE-2025-31254 – A vulnerability in Safari that could lead to unexpected URL redirection when processing malicious web content
– CVE-2025-43272 – A vulnerability in WebKit that could lead to an unexpected crash of Safari when processing malicious web
– CVE-2025-43285 – A permissions vulnerability in AppSandbox that could allow an application to access protected user data
– CVE-2025-43349 – An out-of-bounds write issue in CoreAudio that could lead to an unexpected application termination when processing a malicious video file
– CVE-2025-43316 – A permissions vulnerability in DiskArbitration that could allow an application to gain root privileges
– CVE-2025-43297 – A type confusion vulnerability in Power Management that could lead to a denial-of-service
– CVE-2025-43204 – A vulnerability in RemoteViewServices that could allow an application to escape its sandbox
– CVE-2025-43358 – A permissions vulnerability in Shortcuts that could allow a shortcut to bypass sandbox restrictions
– CVE-2025-43333 – A permissions vulnerability in Spotlight that could allow an application to gain root privileges
– CVE-2025-43304 – A race condition vulnerability in StorageKit that could allow an application to gain root privileges
– CVE-2025-48384 – A vulnerability in Git in Xcode that could lead to remote code execution when cloning a malicious repository
See also: Vulnerabilities in Spring Security Framework bypass authorization

Even though there is no evidence that any of the aforementioned vulnerabilities have been used in real attacks, it is always good practice to keep systems updated for optimal protection.
Apple recommends applying security updates on both new and older devices.
