Executive brief
Apple has released security updates for iOS, iPadOS, and macOS to address a vulnerability that occurs when processing images. An attacker could potentially execute malicious code on a user's device if the user opens a specially crafted image file. This could lead to a full system compromise, unauthorized data access, or service disruptions.
Technical details
An integer overflow vulnerability exists in the image processing components of multiple Apple operating systems, including iOS, iPadOS, and macOS. The issue stems from insufficient input validation when handling image files. A remote attacker can exploit this by enticing a user to open or process a maliciously crafted image, leading to an integer overflow and subsequent arbitrary code execution. Apple has addressed this vulnerability by improving input validation in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: disclosed: Initial advisory publication by Apple
- 2026-07-27: patched: Fixes released in various OS updates