Junglewise Threat Intelligence

CVE-2026-65344: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-65344 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple's Accelerate Framework contains an out-of-bounds write vulnerability in its image processing code. An attacker can craft a malicious image file that, when processed by an application, causes unexpected termination or potential code execution. This affects iPhones, iPads, and Macs running the affected OS versions.

Technical details

This is a heap-based out-of-bounds write vulnerability in the Accelerate Framework's image processing module (CVE-2026-65344, also listed as CVE-2026-86882). The vulnerability exists due to insufficient bounds checking when processing image data. An attacker can provide a maliciously crafted image file that triggers out-of-bounds memory writes, potentially leading to process termination or arbitrary code execution. The attack vector is local and user-initiated (requires opening or processing a malicious image), with no elevated privileges needed. Apple addressed this issue with improved bounds checking in iOS 27/iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27, all released on 2026-09-14.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats