Apple has backported a fix for CVE-2025-43300, an ImageIO out-of-bounds write vulnerability exploited in sophisticated attacks targeting specific individuals. The flaw was chained with a WhatsApp vulnerability (CVE-2025-55177) in highly-targeted spyware campaigns affecting fewer than 200 users. Updates are now available for both current and older iOS, iPadOS, and macOS devices.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Italian digital forensics firm Forenser reported a zero-click campaign targeting iPhones running iOS 16 that hijacked WhatsApp accounts without user interaction. The attackers allegedly exploited CVE-2025-43300 in ImageIO, and possibly CVE-2025-55177, to extract cryptographic material, instantiate rogue WhatsApp sessions, and send fraudulent money-transfer requests from victims' accounts.
Apple released security updates to fix a decade-old iOS zero-day vulnerability that had been exploited in the wild. The patch disclosure marks the first substantive event captured for this story.
A GitHub repository publicly described the 'Glass Cage' zero-click PNG-based iOS 18.2.1 exploit chain, linking ImageIO, WebKit, and Core Media flaws to achieve sandbox escape, kernel-level access, and device compromise via iMessage. The publication exposed technical details of the attack chain before Apple's later patch release.
Initial story creation
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourcegithub.com
Open sourcethecyberthrone.in
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.