Executive brief
A vulnerability in macOS Sequoia could allow a malicious image file to corrupt system memory. If a user opens or processes a specially crafted image, it could lead to a complete system compromise or unauthorized access to data. This issue affects users running versions of macOS Sequoia prior to 15.6.
Technical details
A memory corruption vulnerability (CWE-119) exists in macOS Sequoia due to improper memory handling when processing image files. The flaw can be triggered by a remote attacker if a user is enticed to process a maliciously crafted image, leading to process memory corruption. This could potentially result in arbitrary code execution or a denial-of-service condition. The issue was addressed in macOS Sequoia 15.6 through improved memory handling.
Affected products
- Apple macOS Sequoia up to (excluding) 15.6
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory
- 2026-04-02: patched: Fixed in macOS Sequoia 15.6