Executive brief
The Accelerate Framework is a core system library used by iOS and iPadOS to process images and perform mathematical computations on Apple devices. A flaw in bounds checking allows a remote attacker to trigger an out-of-bounds write by crafting a malicious image, potentially causing app crashes or arbitrary code execution on affected devices.
Technical details
An out-of-bounds write vulnerability exists in Apple's Accelerate Framework component, which handles image processing. The vulnerability is triggered when processing a maliciously crafted image file, allowing an attacker to write data beyond allocated buffer boundaries. The attack vector is remote (image delivery) and does not require prior authentication or user interaction beyond opening/processing the image. Successful exploitation can lead to unexpected process termination or arbitrary code execution with the privileges of the affected process. The vulnerability has been patched in iOS 27, iPadOS 27, macOS Golden Gate 27, and later OS versions.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: iOS 27, iPadOS 27, and related macOS versions released with patch