Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Microsoft adds Copilot-powered debugging features for .NET in Visual Studio

      August 21, 2025

      Blackstone portfolio company R Systems Acquires Novigo Solutions, Strengthening its Product Engineering and Full-Stack Agentic-AI Capabilities

      August 21, 2025

      HoundDog.ai Launches Industry’s First Privacy-by-Design Code Scanner for AI Applications

      August 21, 2025

      The Double-Edged Sustainability Sword Of AI In Web Design

      August 20, 2025

      How VPNs are helping people evade increased censorship – and much more

      August 22, 2025

      Google’s AI Mode can now find restaurant reservations for you – how it works

      August 22, 2025

      Best early Labor Day TV deals 2025: Save up to 50% on Samsung, LG, and more

      August 22, 2025

      Claude wins high praise from a Supreme Court justice – is AI’s legal losing streak over?

      August 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Preserving Data Integrity with Laravel Soft Deletes for Recovery and Compliance

      August 22, 2025
      Recent

      Preserving Data Integrity with Laravel Soft Deletes for Recovery and Compliance

      August 22, 2025

      Quickly Generate Forms based on your Eloquent Models with Laravel Formello

      August 22, 2025

      Pest 4 is Released

      August 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      FOSS Weekly #25.34: Mint 22.2 Features, FreeVPN Fiasco, Windows Update Killing SSDs, AI in LibreOffice and More

      August 21, 2025
      Recent

      FOSS Weekly #25.34: Mint 22.2 Features, FreeVPN Fiasco, Windows Update Killing SSDs, AI in LibreOffice and More

      August 21, 2025

      You’ll need standalone Word, PowerPoint, Excel on iOS, as Microsoft 365 app becomes a Copilot wrapper

      August 21, 2025

      Microsoft to Move Copilot Previews to iOS While Editing Returns to Office Apps

      August 21, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Apple Patches Zero-Day in iOS 18.6.2 After Targeted Exploits Involving Malicious Image Files

    Apple Patches Zero-Day in iOS 18.6.2 After Targeted Exploits Involving Malicious Image Files

    August 21, 2025

    iOS 18.6.2, Zero-Day, Spyware, Security Update

    Apple on Wednesday released iPadOS/iOS 18.6.2, as a security update addressing a zero-day vulnerability— tracked as CVE-2025-43300. The company said, the bug has already been exploited in a sophisticated attack against targeted users.

    The Cupertino-based tech giant’s security patch raised alarms due to a critical flaw in Apple’s ImageIO framework, a component used to process image files on a majority version of iPhones and iPads, in use. The vulnerability involves an out-of-bounds write, meaning a maliciously crafted image could overwrite memory and thus enable remote code execution.

    Apple confirmed the flaw was fixed by improving bounds checking and noted that it had received credible information suggesting exploitation in a targeted manner.

    “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

    The phrase “extremely sophisticated attack” indicates that the flaw could be linked to a broader operation, potentially carried out by nation-state hackers or advanced persistent threat groups focused on high-profile targets. Such wording is generally used only for the most severe security incidents.

    Apple’s zero-days have been notoriously been leveraged in the past by spyware vendors who under the cloak of national security interests, helped several authoritarian governments spy on the people from opposition, journalists, intellectuals and activists from various domains.

    Read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

    Apple’s policy of withholding details until a patch is available is in full force here. The launch of iOS 18.6.2 on Wednesday signals that the company took swift internal action to deploy defenses before public disclosure. The update is available for iPhone XS and later models, as well as iPad Pro and iPad models dating back to the 3rd-gen Pro and iPad 7th generation.

    Patches applicable for:

    • iPhone XS and later
    • iPad Pro 13-inch
    • iPad Pro 12.9-inch 3rd generation and later
    • iPad Pro 11-inch 1st generation and later
    • iPad Air 3rd generation and later
    • iPad 7th generation and later, and
    • iPad mini 5th generation and later

    The fact that attackers exploited something as mundane as an image file shows how modern zero-day campaigns aim for stealth and ubiquity. With images being rendered automatically across apps, browsers, and messaging platforms, the attack surface becomes nearly invisible to the end user.

    Apple’s fast patch rollout may have blunted this particular threat, but it also highlights the ongoing tug of war between device makers and attackers who are constantly seeking new ways to exploit everyday features for high-value gains.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleHackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger
    Next Article DOM-Based Extension Clickjacking Exposes Millions of Password Manager Users to Credential Theft

    Related Posts

    Development

    Preserving Data Integrity with Laravel Soft Deletes for Recovery and Compliance

    August 22, 2025
    Development

    Quickly Generate Forms based on your Eloquent Models with Laravel Formello

    August 22, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-53192 – Apache Commons OGNL Arbitrary Code Execution Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Love Metaphor: ReFantazio? HYTE has a new PC case and accessories for you.

    News & Updates

    Learn Kubernetes – Full Handbook for Developers, Startups, and Businesses

    Development

    CVE-2025-4350 – D-Link DIR-600L Wake-on-LAN Command Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    Why the road from passwords to passkeys is long, bumpy, and worth it – probably

    April 25, 2025

    The passkey standard has reached a precarious moment. Let’s not blow it, OK? Source: Latest…

    Apple Zero-Days Under ‘Sophisticated Attack,’ but Details Lacking

    April 20, 2025

    CVE-2025-47245 – BlueWave Checkmate Role Tampering Vulnerability

    May 3, 2025

    10 Reasons to Choose Full-Stack Techies for Your Next React.js Development Project

    July 9, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.