Apple has released urgent security updates to address a critical vulnerability in its FontParser component, identified as CVE-2025-43400. This flaw affects a wide range of Apple operating systems, including iOS, iPadOS, macOS, visionOS, watchOS, and tvOS. The vulnerability is an out-of-bounds write issue in the system font parser, which could allow a maliciously crafted font file to cause unexpected application crashes or corrupt process memory. Security experts warn that, while there is no evidence of active exploitation, similar vulnerabilities have previously been leveraged for jailbreaks and spyware attacks. The flaw was discovered internally by Apple, and the company has not reported any incidents of it being exploited in the wild. Updates have been released for iOS 26.0.1 and 18.7.1, iPadOS 26.0.1 and 18.7.1, macOS Tahoe 26.0.1, Sequoia 15.7.1, and Sonoma 14.8.1, as well as visionOS 26.0.1, watchOS 26.0.2, and tvOS 26.0.1. The updates cover a broad range of devices, including iPhone 11 and later, various iPad Pro, Air, and mini models, and recent Mac computers. The vulnerability stems from insufficient bounds checking in the font processing code, which could potentially be chained with other vulnerabilities to achieve remote code execution. Apple recommends that all users update their devices promptly to mitigate the risk. The update process is straightforward, with instructions provided for iOS, iPadOS, macOS, and Apple Watch users. For macOS, users should utilize the Software Update feature in System Settings or System Preferences, depending on their version. For iOS and iPadOS, updates can be accessed via the Settings app under General > Software Update. Apple Watch users are advised to update through the Watch app on their paired iPhone. Although the watchOS and tvOS updates do not address security issues beyond this vulnerability, users are still encouraged to keep their devices current. The rapid release of these patches following major OS updates highlights Apple's commitment to addressing security issues promptly. Organizations and individual users are urged to deploy these updates as soon as possible to protect against potential exploitation. The vulnerability's technical details emphasize the importance of robust input validation in system components that handle untrusted data, such as font files. Security professionals note that, even in the absence of active attacks, the risk posed by such vulnerabilities warrants immediate action. Apple's internal discovery and swift remediation of CVE-2025-43400 demonstrate proactive security practices in the face of evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following the release, Apple and subsequent reporting urged users to install the updates promptly because font parsing can occur silently in many apps and system processes. Reports noted there was no evidence of active exploitation at the time of disclosure.
On September 29, 2025, Apple published security advisories and released updates to fix CVE-2025-43400 in iOS, iPadOS, macOS, and visionOS. The fixes were issued in iOS 18.7.1, iPadOS 18.7.1, iOS 26.0.1, iPadOS 26.0.1, macOS Tahoe 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, and visionOS 26.0.1, with related updates also available for other Apple platforms.
Apple internally discovered CVE-2025-43400, an out-of-bounds write vulnerability in the FontParser component. The flaw could let a maliciously crafted font crash apps or corrupt process memory, with possible code-execution implications.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberexpress.com
Open sourcemalwarebytes.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.