Apple Patches iOS Zero-Day Exploit Threatening Crypto Wallets via Malicious Images
Apple has rolled out critical updates—iOS 18.6.2, iPadOS 18.6.2, and macOS patches—to address a zero-day vulnerability in the ImageIO framework. The flaw, tracked as CVE-2025-43300, allowed memory corruption and code execution via malicious images, with confirmed exploitation in targeted attacks. The exploit's delivery through everyday channels like messaging apps heightens risks for crypto users, who frequently store seed phrases in photos or clipboards.
Recent malware families like SparkCat and SparkKitty have weaponized optical character recognition to steal crypto credentials from device galleries, underscoring the urgency of this patch. The update introduces improved bounds checking to mitigate the out-of-bounds write vulnerability. Crypto wallet security remains precarious when convenience practices collide with sophisticated exploits.