Apple Patches Critical Zero-Day Flaw Posing Direct Threat to Crypto Users
Apple has issued emergency security updates for iOS, iPadOS, and macOS to address a zero-day vulnerability actively exploited in targeted attacks. The flaw, CVE-2025-43300, resides in the ImageIO framework—a Core component handling image processing across applications. Attackers can trigger memory corruption via malicious images, enabling arbitrary code execution through routine activities like viewing photos in messages or browsers.
Cryptocurrency holders face heightened risks. Seed phrase screenshots, recovery word photos, and wallet QR codes stored in device galleries become low-hanging fruit for attackers. Recent mobile spyware like SparkCat and SparkKitty already demonstrate this threat, using optical character recognition to plunder crypto assets from compromised devices. Apple's patch strengthens bounds checks in ImageIO, but users should immediately update devices and migrate sensitive data from visual storage.