According to Odaily Planet Daily, OneKey founder Yishi issued a warning on the X platform, advising users to update their iOS and macOS to the latest versions as soon as possible. A high-risk zero-day vulnerability has been discovered in the wild. It's not a proof-of-concept (POC), but someone is using it to exploit CVE-2025-43300. The vulnerability works by sending a specially crafted image to the user, allowing out-of-bounds read and write access to the user's device memory. This leads to direct remote exploitation, and the payload is already being run.
A user in the comment section used Grok to verify, and Grok replied: "CVE-2025-43300 is a real Apple zero-day vulnerability that affects iOS, iPadOS, and macOS. Processing malicious images can lead to out-of-bounds memory writes and potential remote code execution. Apple has confirmed reports of complex attacks against specific individuals and released updates in August 2025 (such as iOS 18.6.2). It is recommended to update immediately. Source: Apple support page, NVD, and security reports."
