Impact
Apple’s image processing component can overflow a buffer when handling maliciously crafted images, allowing an attacker to corrupt process memory. This buffer overflow (CWE‑121) may cause crashes or unintended behavior. Apple addressed the issue with improved memory handling, releasing fixes in iOS 18.7.10, 26.5, 26.7; iPadOS 18.7.10, 26.5, 26.7; macOS Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.5; tvOS 26.5; and watchOS 26.5.
Affected Systems
Apple iOS and iPadOS, Apple macOS (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.5), Apple tvOS, and Apple watchOS are affected. Device firmware versions earlier than iOS 18.7.10, iOS 26.7, iPadOS 18.7.10, iPadOS 26.7, macOS releases earlier than Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.5, tvOS 26.5, and watchOS 26.5 contain the vulnerability, and the flaw has been addressed in the releases listed above.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score of < 1% suggests that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious image file, so the likely attack vector is local, via email, messaging, or other file delivery channels. Because the flaw can corrupt process memory, it poses a significant risk if an attacker can convince a user to open the file.
OpenCVE Enrichment