❗️Zero‑click image attack: Apple ships the patch - crypto wallets in the crosshairs
Apple patched a zero‑click Image I/O exploit - update now
Apple shipped fixes for a critical Image I/O flaw: receiving a malicious image (e.g., via iMessage) could trigger automatic processing, no taps required. This is a true zero‑click risk, with heightened impact for crypto users. Updates: iOS/iPadOS 18.6.2 & 17.7.10, macOS Sequoia 15.6.1, Sonoma 14.7.8, Ventura 13.7.8.
Risk summary
Malicious images could trigger out‑of‑bounds memory writes, enabling code execution on the device.
No user interaction needed; iMessage may auto‑process attachments.
What attackers could access
Files and messages.
Passwords and seed phrases.
App control, including crypto wallets and exchanges (irreversible txs increase attacker incentive).
What to do now
Update devices: Settings → General → Software Update (iPhone/iPad); System Settings → General → Software Update (Mac).
After updating: verify wallet settings (no auto‑sign), reboot device.
High‑value targets/suspected compromise: rotate keys/seeds and secure primary accounts (email/cloud) first; document a clear remediation plan.
Why urgency matters
Apple is aware of extremely sophisticated attacks targeting specific individuals.
There’s a patch but no forced update - protection depends on timely action.
#Apple #iOS1862 #macOS #ZeroClick #ImageIO #Security #Crypto #ios