Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted image can corrupt the memory of a process that parses it, potentially allowing an attacker to alter program state or gain arbitrary code execution. The flaw stems from unsafe memory handling, a buffer overflow weakness (CWE-119). If exploited, it could compromise the confidentiality, integrity, or availability of the application or operating system.

Affected Systems

Apple iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6 contain the fix; all earlier releases of these OS families are vulnerable and have no known patch.

Risk and Exploitability

The vulnerability requires a local delivery of a malicious image; the likely attack vector is inferred to be the processing of an image file from an untrusted source by the device. The EPSS score of less than 1% indicates a low probability of exploitation, and the flaw is not listed in CISA KEV. The CVSS score of 7.8 reflects high impact if the flaw is leveraged, and the lack of mitigations in vulnerable processes means that arbitrary code execution is possible when an attacker can supply crafted image data.

Generated by OpenCVE AI on August 17, 2026 at 23:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, or macOS Tahoe 26.6 to apply the memory handling fix.
  • Restrict processing of image files from untrusted or unknown sources until the operating system is updated.
  • If immediate patching is infeasible, isolate image processing services to trusted users and monitor for anomalous memory usage or application crashes.

Generated by OpenCVE AI on August 17, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Malicious Image Processing Can Corrupt Process Memory on Apple iOS, iPadOS, and macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory. The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.
References

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Malicious Image Causing Process Memory Corruption
Weaknesses CWE-121
CWE-122

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Malicious Image Causing Process Memory Corruption
Weaknesses CWE-119
CWE-121
CWE-122
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:57.812Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43733

cve-icon Vulnrichment

Updated: 2026-07-28T14:45:20.496Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:16:58.000

Modified: 2026-08-17T22:17:09.543

Link: CVE-2026-43733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:15:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer