Executive brief
A security vulnerability exists in Apple operating systems including iOS, macOS, tvOS, and watchOS. The flaw allows a maliciously crafted image to cause system instability or application crashes. This could lead to service disruptions or temporary loss of access to device features if a user encounters a harmful image file.
Technical details
A stack-based buffer overflow (CWE-121) exists in multiple Apple operating systems due to improper memory handling during image processing. An attacker can exploit this by providing a maliciously crafted image file, which, when processed by the system, leads to memory corruption. This vulnerability can be triggered remotely without authentication or user interaction (UI:N), primarily impacting system availability. Apple has addressed the issue with improved memory handling in iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5.
Affected products
- Apple iOS and iPadOS Before 26.5
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched