PSA: iOS 18.6.2 patches key security vulnerability

iOS 18.6.2 is now available for iPhone users, and Apple says it includes an important security fix. Here’s what you need to know, and why you should update right away.

iOS 18.6.2 includes crucial security fix

Apple says that iOS 18.6.2 patches a vulnerability that “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” The vulnerability was discovered by Apple itself, not by a third-party security researcher.

The vulnerability impacts the ImageIO system framework, which is responsible for handling images (opening, decoding, displaying them). If a targeted iPhone user were to open a malicious image file, it could cause memory corruption, which could be exploited by hackers.

Here’s Apple’s full explanation of the bug:

ImageIO

Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later

Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2025-43300: Apple

Here’s the full list of software updates released by Apple today, all of which patch this ImageIO vulnerability:

  • iOS 18.6.2
  • iPadOS 18.6.2
  • iPadOS 17.7.10
  • macOS Sequoia 15.6.1
  • macOS Ventura 13.7.8

You can update your iPhone or iPad by opening the Settings app, choosing General, then choosing Software Update. You can update your Mac in the System Settings app.

We recommend updating right away, as Apple says this vulnerability was actively exploited in the wild. There’s no need to fear you were targeted by the vulnerability, but it’s always good to keep your iPhone, iPad, and Mac updated.

My favorite iPhone accessories:

Follow ChanceThreadsBlueskyInstagram, and Mastodon

FTC: We use income earning auto affiliate links. More.

Leave a Reply

Your email address will not be published. Required fields are marked *