Apple Patches Zero-Day Threat in Older iPhones
- Apple has released security updates for several older iPhone and iPad models, addressing a critical security flaw.
- The vulnerability stems from an out-of-bounds write issue, which Apple has addressed with improved bounds checking.
- Apple has stated that it is aware of reports that this vulnerability was exploited in highly sophisticated attacks targeting specific individuals.
Apple Patches Zero-Day Vulnerability in Older iPhones and iPads
Table of Contents
what Happened: Zero-Day Vulnerability discovered and Patched
Apple has released security updates for several older iPhone and iPad models, addressing a critical security flaw. This vulnerability, tracked as CVE-2025-43300, is a zero-day exploit, meaning it was actively exploited in the wild before a patch was available. The updates were released quietly and initially went unnoticed amidst coverage of the newer iOS 18.6.2 and iPadOS 18.6.2 releases.
The vulnerability stems from an out-of-bounds write issue, which Apple has addressed with improved bounds checking. Specifically, processing a maliciously crafted image file can lead to memory corruption.This could allow an attacker to execute arbitrary code on the device, potentially gaining full control.
Apple has stated that it is aware of reports that this vulnerability was exploited in highly sophisticated attacks targeting specific individuals. This suggests the attacks were not widespread but were carefully aimed at high-value targets.
affected devices
The following devices received updates to address the vulnerability:
| Device | Update Version |
|---|---|
| iPhone (iOS 15) | iOS 15.8.5 |
| iPhone (iOS 16) | iOS 16.7.12 |
| iPad (iPadOS 15) | iPadOS 15.8.5 |
| iPad (iPadOS 16) | iPadOS 16.7.12 |
The Broader Context: Connection to Recent iOS 18.6.2/iPadOS 18.6.2 Patches
Interestingly, this zero-day vulnerability is the same one that Apple patched in the recent iOS 18.6.2, iPadOS 18.6.2, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, and macOS Ventura 13.7.8 releases on August 20, 2025. Apple has backported the fix to older devices that are no longer receiving major OS updates, demonstrating a commitment to security even for legacy hardware.
The initial patch for iOS 18.6.2/iPadOS 18.6.2 included a range of security fixes beyond this specific zero-day,highlighting the ongoing effort to
