Junglewise Threat Intelligence

CVE-2026-28990: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macO

CVE-2026-28990 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Apple Tvos, Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for various operating systems to address a vulnerability in ImageIO, the component responsible for processing images. An attacker could exploit this by tricking a user into opening a specially crafted image file, which could lead to memory corruption and potentially allow unauthorized actions on the device. This affects iPhones, iPads, Macs, and other Apple devices, and users are encouraged to update to the latest software versions to protect their data and device stability.

Technical details

A memory corruption vulnerability exists in the ImageIO framework across multiple Apple operating systems, including iOS, iPadOS, and macOS. The flaw is triggered when the system processes a maliciously crafted image file, leading to memory corruption within the affected process. While the advisory does not explicitly name the vulnerability class beyond 'memory corruption,' the fix involved improved memory handling. An attacker can exploit this via a remote vector by providing a crafted image (e.g., via a website or message) that requires user interaction to open or preview. Successful exploitation could lead to arbitrary code execution or a denial-of-service (app termination). The issue is resolved in iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.

Affected products

  • Apple iOS Before 26.5
  • Apple iPadOS Before 26.5
  • Apple macOS Sequoia Before 15.7.7
  • Apple macOS Sonoma Before 14.8.7
  • Apple macOS Tahoe Before 26.5
  • Apple tvOS Before 26.5
  • Apple visionOS Before 26.5
  • Apple watchOS Before 26.5

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: patched
  • 2026-05-11: advisory

References

Related threats