comscore

Alert! This Hidden Flaw In Your iPhone And iPad Could Lead To A Major Security Breach, CERT-In Issues Warning

Indian government's agency CERT-In has issued a warning to iPhone as well as iPad users with a new flaw which can put your device at risk. Here is everything that you need to know.

Published By: Divya | Published: Oct 03, 2025, 02:10 PM (IST)

  • whatsapp
  • twitter
  • facebook
  • whatsapp
  • twitter
  • facebook

India’s cybersecurity watchdog, the Computer Emergency Response Team (CERT-In), has issued a latest warning for Apple users about a newly discovered security flaw in multiple Apple devices. According to CERT-In’s Vulnerability Note (CIVN-2025-0234), the bug affects iPhones, iPads, Macs, and even Vision Pro headsets running on older versions of iOS, iPadOS, macOS, and visionOS.  news Also Read: 6 Little-Known iOS 26 Features That Instantly Make Your iPhone Better

The flaw, classified with a “medium” severity rating, could allow attackers to exploit devices by sending maliciously crafted fonts. If triggered, this vulnerability could crash apps, disrupt services, or cause system instability.  news Also Read: Apple Vision Pro 2 Surfaces In FCC Filing Ahead Of Launch: All That We Know

CERT-In Warning For Apple Users: What Is The Issue?

The issue lies in Apple’s FontParser component, which is responsible for handling fonts in the system. Due to an “out-of-bounds write” flaw, attackers can create harmful fonts that, once processed by a vulnerable device, may corrupt system memory or cause a denial-of-service (DoS) condition. Simply, an attacker could force an app or service on your Apple device to crash or stop responding. While there’s no mention of active exploits yet, CERT-In says that the risk of instability and downtime is real.

The warning applies to Apple iOS and iPadOS versions before 18.7.1 and 26.0.1, macOS Tahoe versions before 26.0.1, macOS Sequoia before 15.7.1, macOS Sonoma before 14.8.1, and visionOS before 26.0.1. Users running these outdated versions are strongly advised to install the latest software patches that Apple has already rolled out.

How will it impact you? It can vary, as some can experience apps crashing, some may face system slowdowns, while others could end up witnessing the complete unavailability of certain features. However, CERT-In categorises this as a medium-risk vulnerability but mentioned that attackers could exploit it remotely.

How To Be Safe

To be safe from the mentioned flaws and vulnerabilities, Apple suggest you: 

  • Update your devices to the latest software version immediately.
  • Always keep in mind to avoid opening files, especially fonts, from untrusted sources.
  • Make sure to enable automatic updates to ensure future fixes are installed promptly.

It must be noted that this is not the first time that FontParser-related issues have been flagged in Apple’s ecosystem. However, with CERT-In formally warning Indian users, makes it important to be addressed seriously. If you’re using an iPhone, iPad, Mac, or Vision Pro, now is the right time to head over to Settings and check for software updates before attackers find a way to misuse this flaw.