Impact
A flaw in Apple’s image handling can corrupt process memory when a maliciously crafted image is processed. The corruption may overwrite critical data structures, potentially allowing attackers to execute arbitrary code or crash the application.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, and visionOS are affected. The vulnerability is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6; earlier releases are unpatched.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is < 1%, so exploitation probability is low but not zero, and the issue is not listed in CISA’s KEV catalog, limiting public exploitation data. The flaw can be triggered by any process that decodes a malicious image, making it a high‑impact local code‑execution vector that an attacker could exploit through malware, phishing, or insecure image sources. Given the potential for memory corruption and the lack of a known exploit, the threat level remains high, warranting immediate remediation.
OpenCVE Enrichment