Executive brief
A vulnerability in Apple's media processing component could allow a maliciously crafted file to crash applications or corrupt system memory. This affects a wide range of Apple devices, including iPhones, iPads, and Macs. In practice, an attacker could exploit this by tricking a user into opening a specifically designed image or video file, potentially leading to unstable system behavior or unauthorized code execution.
Technical details
A memory corruption vulnerability exists in the AppleJPEG component of multiple Apple operating systems. The issue stems from insufficient input validation when parsing maliciously crafted media files. An attacker can exploit this by providing a specially crafted file that, when processed by the system, triggers memory corruption. This may result in a denial-of-service (app termination) or potentially arbitrary code execution through corrupted process memory. The vulnerability was addressed by Apple through improved input validation in the affected components.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory