Junglewise Threat Intelligence

CVE-2026-28940: Apple Multiple Operating Systems memory corruption in ImageIO

CVE-2026-28940 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple Visionos, Apple iPadOS, Apple macOS Sequoia. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, macOS, and other platforms to address a vulnerability in how images are processed. An attacker could exploit this flaw by tricking a user into opening a specially crafted image file, which could lead to memory corruption and potentially allow unauthorized code execution. This could result in a loss of data confidentiality or system stability across affected iPhones, iPads, and Mac computers.

Technical details

A memory corruption vulnerability exists in Apple's ImageIO component across multiple operating systems (iOS, macOS, tvOS, visionOS). The flaw is triggered when the system processes a maliciously crafted image file, leading to memory corruption. According to CISA-ADP, this is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). An attacker can exploit this remotely if a user interacts with the malicious file (UI:R). The issue was addressed through improved memory handling and input validation. Patches are available in iOS 18.7.9, macOS Sequoia 15.7.7, and related version branches.

Affected products

  • Apple iOS before 18.7.9, 26.0 to 26.5
  • Apple iPadOS before 18.7.9, 26.0 to 26.5
  • Apple macOS Sequoia before 15.7.7
  • Apple macOS Tahoe before 26.5
  • Apple tvOS before 26.5
  • Apple visionOS before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats