Impact
A maliciously crafted image can corrupt the memory of a process that parses it, potentially allowing an attacker to alter program state or gain arbitrary code execution. The flaw stems from unsafe memory handling, a buffer overflow weakness (CWE-119). If exploited, it could compromise the confidentiality, integrity, or availability of the application or operating system.
Affected Systems
Apple iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6 contain the fix; all earlier releases of these OS families are vulnerable and have no known patch.
Risk and Exploitability
The vulnerability requires a local delivery of a malicious image; the likely attack vector is inferred to be the processing of an image file from an untrusted source by the device. The EPSS score of less than 1% indicates a low probability of exploitation, and the flaw is not listed in CISA KEV. The CVSS score of 7.8 reflects high impact if the flaw is leveraged, and the lack of mitigations in vulnerable processes means that arbitrary code execution is possible when an attacker can supply crafted image data.
OpenCVE Enrichment