Executive brief
The Accelerate Framework is a low-level library used by many Apple applications to process images and perform mathematical computations. A flaw in its image handling allows specially crafted images to trigger an out-of-bounds memory write, potentially causing applications to crash unexpectedly or enabling more severe attacks on affected systems.
Technical details
CVE-2026-28966 is an out-of-bounds write vulnerability in Apple's Accelerate Framework, a system library responsible for optimized image and signal processing operations. The vulnerability is triggered when the framework processes a maliciously crafted image file that violates expected bounds for memory writes. An attacker can deliver the malicious image via network (e.g., embedded in a web page, email attachment, or messaging app), and when processed by any app using the Accelerate Framework, it causes unexpected app termination (denial of service). While the primary impact listed is app crash, out-of-bounds writes can potentially be leveraged for memory corruption. The fix was implemented through improved bounds checking and is available in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27 released on 2026-09-14.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched