Apple released iOS 18.6.2 to fix a zero-day vulnerability (CVE-2025-43300) in the ImageIO framework that was exploited in sophisticated attacks. The flaw involved out-of-bounds write, allowing remote code execution through malicious images, highlighting the ongoing threat posed by nation-state hackers and advanced persistent threat groups. #CVE202543300 #ImageIOVulnerability
Keypoints
- Appleβs security update addresses a zero-day flaw exploited in targeted attacks.
- The vulnerability exists in the ImageIO framework used by many Apple devices.
- The flaw enables remote code execution via maliciously crafted images.
- Attackers using this exploit are possibly nation-state hackers or advanced threat groups.
- The swift patch deployment underscores the importance of prompt security updates for Apple devices.
Read More: https://thecyberexpress.com/zero-day-patched-in-ios-18-6-2/