
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then WebKit(CVE-2025-24201) and Core Media(CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
Patched: Jan-March 2025
Tested On: iPhone 14 Pro Max (iOS 18.2.1)
VirusTotal Analysis (Verified Hash)
Glass Cage is a critical, zero-click PNG-based exploit chain discovered in the wild targeting iOS 18.2.1. The attack was actively observed on a compromised device and confirmed to be used against real-world targets prior to vendor patching.
A malicious PNG image sent via iMessage initiates the chain by triggering automatic parsing in MessagesBlastDoorService (CVE-2025-43300). The image exploits a WebKit heap corruption vulnerability (CVE-2025-24201), followed by a sandbox escape and a kernel-level privilege escalation in Core Media (CVE-2025-24085).
The chain ultimately provides attackers with root-level access, persistent control, keychain exfiltration, and even the ability to irreversibly brick devices via IORegistry manipulation. No user interaction is required.
https://ia600508.us.archive.org/8/items/cve-2025-24085-24201/cve%202025-24085%3B%2024201.mov
Malicious PNG Creation
ATXEncoder (CVE-2025-43300)Silent Trigger via iMessage
MessagesBlastDoorServiceSandbox Escape
Privilege Escalation
mediaplaybackd, codecctl, and IOHIDInterface (CVE-2025-24085)Persistence and Bricking
launchdwifid172.16.101.176wifidCloudKeychainProxyIOAccessoryPowerSourceItemBrickLimit = 0This exploit chain was discovered being used in the wild and responsibly disclosed to Apple. Patches have since been released. At the time of discovery, active exploitation was confirmed.
This research has been independently verified and certified by the China National Vulnerability Database (CNVD). These official certificates confirm the high-risk status of both vulnerabilities used in the Glass Cage exploit chain:
CNVD-2025-07885 – Use-After-Free in Apple Media Services
CNVD-2025-06744 – Buffer Overflow in Apple iOS/iPadOS Core Media
Researcher: Joseph Goydish II
Submission Type: Personal Researcher Submission
Certification Authority: CNCERT / CNVD
iMessage creates a thumbnail and incoming-text alert as soon as a message is delivered, and that thumbnail is parsed automatically. If that parsing can be weaponized, mere delivery (thumbnail + alert) is enough for instant, silent compromise — no user action, no warning.
| Date | Event |
|---|
| Dec 18, 2024 | Exploit chain observed in the wild & reported |
| Jan 9, 2025 | Initial report re-submitted to US Cert & Apple |
| Feb 20, 2025 | CVE-2025-24085 patched (Core Media) |
| Mar 11, 2025 | CVE-2025-24201 patched (WebKit) |
| Mar 18, 2025 | CNVD-2025-06744 registered |
| Apr 22, 2025 | CNVD-2025-07885 registered |