Close Menu
TechurzTechurz
    What's Hot

    Bot-detection startup Spur nabs $200M from Insight

    July 28, 2026

    MCP startup Runlayer accuses Rippling of stealing its product idea

    July 28, 2026

    Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy

    July 28, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Bot-detection startup Spur nabs $200M from Insight
    • MCP startup Runlayer accuses Rippling of stealing its product idea
    • Ozlo’s Sleepbuds 2 build on Bose’s sleep earbud legacy
    • Cursor makes its biggest India push yet ahead of SpaceX acquisition with localized pricing
    • Antares raises $470M to build nuclear reactors for the US military
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack
    Cyber Reality

    Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

    TechurzBy TechurzSeptember 17, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Sep 16, 2025Ravie LakshmananVulnerability / Spyware

    Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild.

    The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component that could result in memory corruption when processing a malicious image file.

    “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals,” the company said.

    Since then, WhatsApp has acknowledged that a vulnerability in its messaging apps for Apple iOS and macOS (CVE-2025-55177, CVSS score: 5.4) had been chained with CVE-2025-43300 as part of highly-targeted spyware attacks aimed at less than 200 individuals.

    While the shortcoming was first addressed by the iPhone maker late last month with the release of iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Ventura 13.7.8, macOS Sonoma 14.7.8, and macOS Sequoia 15.6.1, it has also been released for the following older versions –

    • iOS 16.7.12 and iPadOS 16.7.12 – iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
    • iOS 15.8.5 and iPadOS 15.8.5 – iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

    The updates have been rolled out alongside iOS 26, iPadOS 26, iOS 18.7, iPadOS 18.7, macOS Tahoe 26, macOS Sequoia 15.7, macOS Sonoma 14.8, tvOS 26, visionOS 26, watchOS 26, Safari 26, and Xcode 26, which also address a number of other security flaws –

    • CVE-2025-31255 – An authorization vulnerability in IOKit that could allow an app to access sensitive data
    • CVE-2025-43362 – A vulnerability in LaunchServices that could allow an app to monitor keystrokes without user permission
    • CVE-2025-43329 – A permissions vulnerability in Sandbox that could allow an app to break out of its sandbox
    • CVE-2025-31254 – A vulnerability in Safari that could result in unexpected URL redirection when processing maliciously crafted web content
    • CVE-2025-43272 – A vulnerability in WebKit that could result in unexpected Safari crash when processing maliciously crafted web content
    • CVE-2025-43285 – A permissions vulnerability in AppSandbox that could allow an app to access protected user data
    • CVE-2025-43349 – An out-of-bounds write issue in CoreAudio that could result in unexpected app termination when processing a maliciously crafted video file
    • CVE-2025-43316 – A permissions vulnerability in DiskArbitration that could allow an app to gain root privileges
    • CVE-2025-43297 – A type confusion vulnerability in Power Management that could result in a denial-of-service
    • CVE-2025-43204 – A vulnerability in RemoteViewServices that could allow an app to break out of its sandbox
    • CVE-2025-43358 – A permissions vulnerability in Shortcuts that could allow a shortcut to bypass sandbox restrictions
    • CVE-2025-43333 – A permissions vulnerability in Spotlight that could allow an app to gain root privileges
    • CVE-2025-43304 – A race condition vulnerability in StorageKit that could allow an app to gain root privileges
    • CVE-2025-48384 – A Git vulnerability in Xcode that could result in remote code execution when cloning a maliciously crafted repository

    While there is no evidence that any of the aforementioned flaws have been weaponized in real-world attacks, it’s always a good practice to keep systems up-to-date for optimal protection.

    Apple Attack Backports CVE202543300 exploited fix sophisticated spyware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow People Are Using ChatGPT: OpenAI Study
    Next Article Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move
    Techurz
    • Website

    Related Posts

    Opinion

    Backed by $60M in funding, Oak steps out of stealth to fix the identity mess that AI agents are making worse

    July 15, 2026
    Opinion

    Robotaxis drive miles just to get cleaned and charged; this new startup wants to fix that

    June 26, 2026
    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.