
Written By Divya
Published By: Divya | Published: Oct 03, 2025, 02:10 PM (IST)
India’s cybersecurity watchdog, the Computer Emergency Response Team (CERT-In), has issued a latest warning for Apple users about a newly discovered security flaw in multiple Apple devices. According to CERT-In’s Vulnerability Note (CIVN-2025-0234), the bug affects iPhones, iPads, Macs, and even Vision Pro headsets running on older versions of iOS, iPadOS, macOS, and visionOS. Also Read: 6 Little-Known iOS 26 Features That Instantly Make Your iPhone Better
The flaw, classified with a “medium” severity rating, could allow attackers to exploit devices by sending maliciously crafted fonts. If triggered, this vulnerability could crash apps, disrupt services, or cause system instability. Also Read: Apple Vision Pro 2 Surfaces In FCC Filing Ahead Of Launch: All That We Know
The issue lies in Apple’s FontParser component, which is responsible for handling fonts in the system. Due to an “out-of-bounds write” flaw, attackers can create harmful fonts that, once processed by a vulnerable device, may corrupt system memory or cause a denial-of-service (DoS) condition. Simply, an attacker could force an app or service on your Apple device to crash or stop responding. While there’s no mention of active exploits yet, CERT-In says that the risk of instability and downtime is real.
The warning applies to Apple iOS and iPadOS versions before 18.7.1 and 26.0.1, macOS Tahoe versions before 26.0.1, macOS Sequoia before 15.7.1, macOS Sonoma before 14.8.1, and visionOS before 26.0.1. Users running these outdated versions are strongly advised to install the latest software patches that Apple has already rolled out.
How will it impact you? It can vary, as some can experience apps crashing, some may face system slowdowns, while others could end up witnessing the complete unavailability of certain features. However, CERT-In categorises this as a medium-risk vulnerability but mentioned that attackers could exploit it remotely.
To be safe from the mentioned flaws and vulnerabilities, Apple suggest you:
It must be noted that this is not the first time that FontParser-related issues have been flagged in Apple’s ecosystem. However, with CERT-In formally warning Indian users, makes it important to be addressed seriously. If you’re using an iPhone, iPad, Mac, or Vision Pro, now is the right time to head over to Settings and check for software updates before attackers find a way to misuse this flaw.