Apple has released critical security updates across iOS, iPadOS, and macOS to address a high-severity zero-day flaw (CVE-2025-43300) that has reportedly been exploited in “extremely sophisticated attacks against specific targeted individuals.”
What’s the Vulnerability?
The flaw sits in Apple’s Image I/O framework, the bit of software that processes images across iPhones, iPads, and Macs. In plain terms: attackers can hide malicious code inside an image. If a user opens that image, it could corrupt memory and potentially give hackers remote access.
Apple has released patches for:
- iOS 18.6.2 and iPadOS 18.6.2, plus iPadOS 17.7.10
- macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8
Why Businesses Should Act Now
Even though Apple hasn’t disclosed full technical details, there’s a clear pattern: flaws that start out in elite, targeted attacks often become weaponised by cybercriminals in broader campaigns.
That means these updates aren’t just for high-profile individuals – they’re essential for every business user. The longer you wait, the bigger the window of opportunity for attackers.
Broader Context: A Pattern of Rapid Zero-Day Exploits
This vulnerability marks one among several Apple has addressed in 2025. It follows patches for core system flaws (such as CVE-2025-31200 and CVE-2025-31201) used in similarly “extremely sophisticated” attacks and others patched earlier in the year.
What Dr Logic Recommends
For firms managing their own IT, the key steps are clear:
- Prioritise updates: Ensure your devices run the latest OS versions listed above.
- Enable auto-updates: Reduce lag in deployment by turning on automatic updates.
- Communicate urgency: Make sure staff understand that even something as simple as an image file can carry risk.
- Reinforce best practice: Schedule downtime for patching, check backups, and maintain readiness.
Peace of Mind for Dr Logic Customers
If you’re a Dr Logic customer, you don’t need to worry. We handle updates for you as part of our proactive cyber security service. Our team applies patches quickly and consistently, so your business stays secure without disruption.
That means:
- No chasing staff to update devices.
- No lost productivity.
- No sleepless nights wondering if your systems are exposed.
We keep watch, so you can focus on running your business.
Want the Same Peace of Mind?
Book a cyber health check with Dr Logic and let’s make sure your business is protected from today’s threats – and tomorrow’s.