Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted image can corrupt the memory of a process that parses it, leading to unintended behavior or execution of arbitrary code. The flaw arises from unsafe memory handling, classifying it as a buffer overflow or stack-based overflow type weakness. If exploited, an attacker could alter program state, compromise confidentiality, integrity, or availability of the affected application or operating system.

Affected Systems

Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6 contain the fix; all earlier releases are vulnerable and have no known patch. Systems running those unpatched versions remain at risk when processing untrusted image files.

Risk and Exploitability

The vulnerability requires local delivery of a malicious image; it does not involve a network component. The EPSS score of less than 1% indicates a low probability of exploitation, and the flaw is not listed in CISA KEV. The CVSS score of 7.8 reflects a high impact if the flaw is leveraged, and the lack of mitigations in the vulnerable processes means that arbitrary code execution is possible if an attacker can supply crafted image data.

Generated by OpenCVE AI on August 3, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, or macOS Tahoe 26.6 to apply the memory handling fix.
  • Restrict processing of image files from untrusted or unknown sources until the operating system is updated.
  • If immediate patching is infeasible, isolate image processing services to trusted users and monitor for anomalous memory usage or application crashes.

Generated by OpenCVE AI on August 3, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Malicious Image Causing Process Memory Corruption
Weaknesses CWE-121
CWE-122

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Malicious Image Causing Process Memory Corruption
Weaknesses CWE-119
CWE-121
CWE-122
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:45:29.520Z

Reserved: 2026-05-01T22:46:21.646Z

Link: CVE-2026-43733

cve-icon Vulnrichment

Updated: 2026-07-28T14:45:20.496Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:58.000

Modified: 2026-07-28T19:31:56.480

Link: CVE-2026-43733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer