The National Computer Emergency Response Team (NCERT) has sounded the alarm on a dangerous zero-day vulnerability affecting Apple devices, including iPhones, iPads, and MacBooks. The flaw, tracked as CVE-2025-43300, exists in Appleās ImageIO framework and is currently being exploited in the wild.
According to NCERT, this high-risk vulnerability allows attackers to remotely take control of a device simply by getting the user to open a specially crafted image file. The exploit can cause memory corruption, enable unauthorized access, and lead to the exposure of sensitive data ā all without requiring special permissions.
Devices at Risk
The vulnerability was originally identified in iOS 17.4 and continues to affect multiple versions of Appleās operating systems. Apple has responded by releasing critical security updates to patch the issue:
-
iOS and iPadOS: Update to 18.6.2 or later
-
macOS: Update to Sequoia 15.6.1, Ventura 13.7.8, or Sonoma 14.7.8
Immediate Actions Advised
NCERT urges all users ā both individuals and organizations ā to install the latest updates without delay. For those unable to update immediately, the agency recommends:
-
Avoid opening image files from unknown or untrusted sources
-
Disable automatic image rendering in apps, if possible
-
Monitor for abnormal system crashes or memory issues
-
Enable automatic updates and use MDM tools in enterprise environments
-
Strengthen endpoint monitoring to detect exploitation attempts
While no specific indicators of compromise (IoCs) have been shared yet, NCERT warns that attack campaigns are ongoing, and the window for prevention is closing fast.
Why It Matters
This vulnerability is particularly dangerous due to its ease of exploitation and wide attack surface ā image files are commonly shared and often trusted by users. If exploited, attackers could gain full control of a device, putting both personal and corporate data at serious risk.
NCERTās final message: Apply Appleās latest security patches immediately to safeguard your devices from this active and critical threat.

