Junglewise Threat Intelligence

CVE-2026-65346: Apple ImageIO integer overflow in image processing

CVE-2026-65346 · Severity: high · CVSS 8.8 · Published 2026-08-17

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's ImageIO library processes images across iOS, iPadOS, and macOS devices. An integer overflow vulnerability in image handling allows attackers to execute arbitrary code by crafting a malicious image file, potentially compromising device security and user data.

Technical details

The vulnerability is an integer overflow in ImageIO's image processing logic, addressed through improved input validation. An attacker can trigger arbitrary code execution by providing a specially crafted image file. The vulnerability is remotely exploitable via image processing without requiring special privileges or user interaction beyond opening/processing the image. The issue affects ImageIO framework across iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27, with patches available in these versions.

Affected products

  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched

References

Related threats