Junglewise Threat Intelligence

CVE-2026-65347: Apple ImageIO denial of service via malicious image processing

CVE-2026-65347 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Technologies: Apple Tvos, Apple macOS, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

ImageIO is Apple's image processing framework used across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to handle image files. A malicious or crafted image file can trigger a denial-of-service condition, causing the affected application or system component to become unresponsive or crash, disrupting user operations.

Technical details

CVE-2026-65347 is a denial-of-service vulnerability in Apple's ImageIO framework. The vulnerability occurs when processing a specially crafted image file; the root cause involves insufficient input validation checks. An attacker can craft a malicious image file and deliver it locally or through a network service that processes images, causing the affected process to crash or become unresponsive. The vulnerability requires user interaction (opening or processing the image) and affects multiple Apple platforms. Apple addressed this issue with improved validation checks, and patches are available in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.6.1
  • Apple iPadOS before 26.6.1
  • Apple macOS Tahoe before 26.6.2
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched: iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27

References

Related threats