Executive brief
Apple iOS, iPadOS, and macOS contain a memory corruption vulnerability triggered when processing maliciously crafted images. An attacker can exploit this to cause an application to crash, resulting in denial-of-service and potential service interruption for users. The vulnerability affects multiple Apple operating systems and requires no user authentication beyond normal image viewing or processing.
Technical details
A memory corruption issue exists in the image processing component across Apple's operating systems, caused by insufficient bounds checking. An attacker can craft a malicious image file that, when processed by the system or applications, triggers out-of-bounds memory access. This can lead to a denial-of-service condition where the affected application or system service terminates unexpectedly. The vulnerability requires no special privileges and is triggered through normal image handling workflows. Apple addressed this issue with improved bounds checking in iOS 18.7.10, iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8.
Affected products
- Apple iOS before 18.7.10
- Apple iPadOS before 18.7.10
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.7.8
- Apple macOS Sonoma before 14.8.8
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Patches released for macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8; iOS 18.7.10 and iPadOS 18.7.10 patch date not explicitly stated but referenced as available