Executive brief
Apple has released security updates for iOS, macOS, and other platforms to address a vulnerability in how images are processed. An attacker could exploit this flaw by tricking a user into opening a specially crafted image file, which could lead to memory corruption and potentially allow unauthorized code execution. This could result in a loss of data confidentiality or system stability across affected iPhones, iPads, and Mac computers.
Technical details
A memory corruption vulnerability exists in Apple's ImageIO component across multiple operating systems (iOS, macOS, tvOS, visionOS). The flaw is triggered when the system processes a maliciously crafted image file, leading to memory corruption. According to CISA-ADP, this is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). An attacker can exploit this remotely if a user interacts with the malicious file (UI:R). The issue was addressed through improved memory handling and input validation. Patches are available in iOS 18.7.9, macOS Sequoia 15.7.7, and related version branches.
Affected products
- Apple iOS before 18.7.9, 26.0 to 26.5
- Apple iPadOS before 18.7.9, 26.0 to 26.5
- Apple macOS Sequoia before 15.7.7
- Apple macOS Tahoe before 26.5
- Apple tvOS before 26.5
- Apple visionOS before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory