The National Computer Emergency Response Team (NCERT) has issued an alert over a severe security flaw in Apple’s ImageIO framework, tracked as CVE-2025-43300. This zero-day vulnerability enables attackers to overwrite device memory through a malicious image file, potentially granting them full control over affected iPhones, iPads, and MacBooks.
NCERT reports that the flaw is already being exploited in targeted attacks, posing a high-risk threat to both individual users and organizations. Successful exploitation could result in memory corruption, unauthorized access, system compromise, and data exposure.
The vulnerability can be triggered remotely by deceiving users into opening a specially crafted image—no additional permissions are needed. Apple has released urgent security patches to address the issue and protect users.
Originally discovered in iOS 17.4, the bug persists across several later versions of Apple’s operating systems. NCERT urges all users to update immediately to the latest versions: iOS and iPadOS 18.6.2, macOS Sequoia 15.6.1, Ventura 13.7.8, or Sonoma 14.7.8.
For users who cannot update right away, NCERT recommends:
-
Avoiding image files from unverified or unknown sources
-
Disabling automatic image previews or rendering
-
Monitoring system logs for unusual crashes or memory-related errors
While no indicators of compromise (IoCs) have been shared so far, NCERT advises organizations to remain vigilant for suspicious image activity or unexplained device instability. It also recommends enabling automatic updates, enforcing patch compliance through mobile device management (MDM), and strengthening endpoint monitoring to detect exploit attempts involving image files.
The agency emphasized that prompt patching is essential, warning that delayed updates could lead to complete device compromise and data breaches. Users are strongly urged to install Apple’s latest security updates without delay.















