Junglewise Threat Intelligence

CVE-2026-28981: Apple macOS buffer overflow in image processing

CVE-2026-28981 · Severity: info · Published 2026-07-27

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow an attacker to take control of a computer if a user opens a specially crafted image file. This issue affects the way the operating system processes image data, potentially leading to unauthorized software execution or system instability. Users should update to the latest macOS versions to protect their data and devices.

Technical details

A buffer overflow vulnerability exists in macOS due to insufficient bounds checking during the processing of image files. An attacker can exploit this by tricking a user into opening or previewing a maliciously crafted image, which may lead to arbitrary code execution with the privileges of the current user or process. The issue has been addressed by implementing improved bounds checking in the affected components. This vulnerability impacts macOS Sequoia versions prior to 15.7.8, macOS Sonoma versions prior to 14.8.8, and macOS Tahoe versions prior to 26.6.

Affected products

  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats