Junglewise Threat Intelligence

CVE-2026-43818: Apple iOS and macOS arbitrary code execution in image processing

CVE-2026-43818 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for iOS, iPadOS, and macOS to address a vulnerability that occurs when processing images. An attacker could potentially execute malicious code on a user's device if the user opens a specially crafted image file. This could lead to a full system compromise, unauthorized data access, or service disruptions.

Technical details

An integer overflow vulnerability exists in the image processing components of multiple Apple operating systems, including iOS, iPadOS, and macOS. The issue stems from insufficient input validation when handling image files. A remote attacker can exploit this by enticing a user to open or process a maliciously crafted image, leading to an integer overflow and subsequent arbitrary code execution. Apple has addressed this vulnerability by improving input validation in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6

Timeline

  • 2026-07-27: disclosed: Initial advisory publication by Apple
  • 2026-07-27: patched: Fixes released in various OS updates

References

Related threats