Junglewise Threat Intelligence

CVE-2026-28977: Apple Multiple Operating Systems denial of service in ImageIO

CVE-2026-28977 · Severity: medium · CVSS 6.2 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates to address a vulnerability in ImageIO, a component used for processing images across various Apple operating systems. If a user opens a maliciously crafted file, it could cause the application to crash unexpectedly. This issue primarily impacts system stability and availability rather than data privacy.

Technical details

A vulnerability exists in the ImageIO framework across multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS). The flaw is rooted in insufficient bounds checking during the processing of files. An attacker can exploit this by providing a maliciously crafted file to a vulnerable application, leading to an out-of-bounds access and subsequent application termination (Denial of Service). The issue was addressed by Apple through improved bounds checks in the affected components. Exploitation requires a user to open or process the malicious file.

Affected products

  • Apple iOS 18.7.9, 26.5
  • Apple iPadOS 18.7.9, 26.5
  • Apple macOS Sequoia 15.7.7
  • Apple macOS Sonoma 14.8.7
  • Apple macOS Tahoe 26.5
  • Apple tvOS 26.5
  • Apple visionOS 26.5
  • Apple watchOS 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched

References

Related threats