Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Malicious Fonts Could Hijack Your Apple Device—Update Now!
Facebook   X   LinkedIn   Email

Malicious Fonts Could Hijack Your Apple Device—Update Now!

November 11, 2025

Apple recently released urgent security updates for all iPhone users, who are strongly urged to update immediately. Both iOS 26.0.1 and iOS 18.7.1 (the latest versions) address a serious security flaw that could allow hackers to compromise your device simply by tricking you into viewing malicious content.

The vulnerability exists in FontParser, Apple's system for processing fonts. Sounds harmless, right? Wrong. This security hole means that opening an email, document, or even visiting a website containing a specially crafted malicious font could corrupt your phone's memory or crash apps unexpectedly. In the wrong hands, this type of vulnerability becomes a gateway for cybercriminals to access your personal information, banking apps, and sensitive data.

Apple identified the flaw internally and assigned it the designation CVE-2025-43400. The company fixed it by improving bounds checking—essentially putting up better guardrails to prevent malicious fonts from writing data where they shouldn't. The vulnerability affects iPhone XS and later models, which means if you've purchased an iPhone in the last several years, you're at risk until you update.

For those who haven't yet upgraded to iOS 26, don't worry—iOS 18.7.1 includes the same critical security fix, ensuring older operating system users are protected too.

Why You Can't Wait

Font-based exploits aren't theoretical threats—they're real-world attacks that cybercriminals actively use. The malicious content can be hidden in PDFs, embedded in emails, or lurking on compromised websites. You might never know you've been targeted until it's too late.

The good news? Installing the update takes just a few minutes. Go to Settings, then General, then Software Update. Download and install the update, restart your phone, and you're protected. It's that simple.

With vulnerabilities like this affecting millions of devices, hackers are already scanning for unpatched iPhones. Don't make yourself an easy target. Update now and keep your personal information where it belongs—private.


Apple Patches Dangerous Zero-Day—Update Now!

Mobile Security

Apple Patches Dangerous Zero-Day—Update Now!

Heads up, Apple users—this one’s a seriously bad apple that can truly ruin the whole bunch. The company just rushed out a patch for a dangerous zero-day flaw, CVE-2025-43300, that’s already being wielded in the wild against targeted individuals; and was even before this patch was available. If your devices are running on any Apple operating system, be it a smartphone, tablet, or computer, take heed of this advice that could prevent you from getting a lot of worms in your fruit. READ FULL STORY

New Malware Sparkles Up Your Android and iOS

Mobile Security

New Malware Sparkles Up Your Android and iOS

Who can you trust these days? Sadly, it’s getting more and more difficult to be sure. However, there are plenty of trustworthy cybersecurity researchers out there, such as those at Kaspersky. They found a mobile trojan just hanging out in the official app stores for the most popular smartphones just waiting to steal all of your photos. And it’s been out there hunting since February of 2024. It’s a follow-up to Kaspersky’s earlier warning about SparkCat spyware.  READ FULL STORY

Apple Releases Critical Update to Thwart Zero-Day Flaw

Your Security

Apple Releases Critical Update to Thwart Zero-Day Flaw

Apple has recently rolled out iOS 18.3.2, a critical update addressing a significant security vulnerability identified as CVE-2025-24201. This issue was discovered earlier this year and remained a zero-day flaw until now. Apple has acknowledged reports indicating that this security gap may have been exploited in highly sophisticated attacks targeting specific individuals, particularly on devices running versions prior to iOS 17.2. The vulnerability could potentially allow malicious actors to perform unauthorized actions on your device. READ FULL STORY

Keeping Your Mobile Device Apps Virus Free

Mobile Security

Keeping Your Mobile Device Apps Virus Free

It’s no secret that cybercriminals take advantage of anxiety-filled times and the current coronavirus pandemic (COVID-19) is most certainly one of those moments. The latest cybersecurity news reports that Android smartphones are being targeted with apps claiming to have up-to-date data on COVID-19. These infected apps promise the latest updates, but to unsuspecting users who download them, they also promise malware will surely be installed on your mobile device. READ FULL STORY

One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?

Mobile Security

One Billion+ Android App Downloads Are Hiding Banking Trojans. Is One Yours?

With over one billion trojan banking malware downloads from 639 apps on Google Play Store, it’s time for mobile Android users to pay attention. After all, it’s ultimately the victims who end up paying the price for Google not finding the malware before making it available on their Play Store. Despite Google’s recently improved efforts to keep malware out of their App Store, like introducing Play Protect, it appears there’s a lot more work to be done. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...