Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Error’d: Pickup Sticklers

      September 27, 2025

      From Prompt To Partner: Designing Your Custom AI Assistant

      September 27, 2025

      Microsoft unveils reimagined Marketplace for cloud solutions, AI apps, and more

      September 27, 2025

      Design Dialects: Breaking the Rules, Not the System

      September 27, 2025

      Building personal apps with open source and AI

      September 12, 2025

      What Can We Actually Do With corner-shape?

      September 12, 2025

      Craft, Clarity, and Care: The Story and Work of Mengchu Yao

      September 12, 2025

      Cailabs secures €57M to accelerate growth and industrial scale-up

      September 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025
      Recent

      Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

      September 28, 2025

      Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

      September 28, 2025

      The first browser with JavaScript landed 30 years ago

      September 27, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured
      Recent
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Apple Patches Zero-Day in iOS 18.6.2 After Targeted Exploits Involving Malicious Image Files

    Apple Patches Zero-Day in iOS 18.6.2 After Targeted Exploits Involving Malicious Image Files

    August 21, 2025

    iOS 18.6.2, Zero-Day, Spyware, Security Update

    Apple on Wednesday released iPadOS/iOS 18.6.2, as a security update addressing a zero-day vulnerability— tracked as CVE-2025-43300. The company said, the bug has already been exploited in a sophisticated attack against targeted users.

    The Cupertino-based tech giant’s security patch raised alarms due to a critical flaw in Apple’s ImageIO framework, a component used to process image files on a majority version of iPhones and iPads, in use. The vulnerability involves an out-of-bounds write, meaning a maliciously crafted image could overwrite memory and thus enable remote code execution.

    Apple confirmed the flaw was fixed by improving bounds checking and noted that it had received credible information suggesting exploitation in a targeted manner.

    “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

    The phrase “extremely sophisticated attack” indicates that the flaw could be linked to a broader operation, potentially carried out by nation-state hackers or advanced persistent threat groups focused on high-profile targets. Such wording is generally used only for the most severe security incidents.

    Apple’s zero-days have been notoriously been leveraged in the past by spyware vendors who under the cloak of national security interests, helped several authoritarian governments spy on the people from opposition, journalists, intellectuals and activists from various domains.

    Read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

    Apple’s policy of withholding details until a patch is available is in full force here. The launch of iOS 18.6.2 on Wednesday signals that the company took swift internal action to deploy defenses before public disclosure. The update is available for iPhone XS and later models, as well as iPad Pro and iPad models dating back to the 3rd-gen Pro and iPad 7th generation.

    Patches applicable for:

    • iPhone XS and later
    • iPad Pro 13-inch
    • iPad Pro 12.9-inch 3rd generation and later
    • iPad Pro 11-inch 1st generation and later
    • iPad Air 3rd generation and later
    • iPad 7th generation and later, and
    • iPad mini 5th generation and later

    The fact that attackers exploited something as mundane as an image file shows how modern zero-day campaigns aim for stealth and ubiquity. With images being rendered automatically across apps, browsers, and messaging platforms, the attack surface becomes nearly invisible to the end user.

    Apple’s fast patch rollout may have blunted this particular threat, but it also highlights the ongoing tug of war between device makers and attackers who are constantly seeking new ways to exploit everyday features for high-value gains.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleHackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger
    Next Article DOM-Based Extension Clickjacking Exposes Millions of Password Manager Users to Credential Theft

    Related Posts

    Development

    Using phpinfo() to Debug Common and Not-so-Common PHP Errors and Warnings

    September 28, 2025
    Development

    Mastering PHP File Uploads: A Guide to php.ini Settings and Code Examples

    September 28, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

    Development

    Intelligent Parsing and Formatting of Names in PHP Applications

    Development

    High-Severity Flaw in HashiCorp Nomad (CVE-2025-4922) Allows Privilege Escalation

    Security

    15 Git Commands That Cover 90% of a Developer’s Daily Workflow

    Web Development

    Highlights

    This Sony OLED TV is my pick for best Prime Day deal – and it’s the last chance to get 50% off

    July 9, 2025

    Here’s why I recommend this Sony OLED over newer models, and why it’s the best…

    ⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & More

    August 4, 2025

    Simplify API Responses with Fluent Methods

    June 6, 2025

    Customer Onboarding Beyond KYC: Accelerating Insurance Revenue with End-to-End Application Automation

    August 22, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.