Executive brief
A vulnerability in macOS Sequoia could allow a malicious actor to compromise a system when a user processes a specially crafted image. This could lead to unauthorized access to sensitive data, system instability, or the execution of malicious code. Users are advised to update to macOS Sequoia 15.6 to mitigate this risk.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in macOS Sequoia due to improper memory handling when processing image files. An attacker can exploit this by tricking a user into opening or previewing a maliciously crafted image, leading to process memory corruption. This vulnerability can potentially be leveraged for remote code execution (RCE) with the privileges of the affected process. The issue was addressed in macOS Sequoia 15.6 through improved memory handling.
Affected products
- Apple macOS Sequoia up to (excluding) 15.6
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory
- 2026-04-02: patched: Fixed in macOS Sequoia 15.6