Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in texture processing causes an integer overflow that can be triggered with a maliciously crafted texture file, resulting in unexpected application termination. The flaw is classified as CWE-190 and does not allow arbitrary code execution.

Affected Systems

Apple’s iOS and iPadOS devices running a version prior to 26.6, macOS Sequoia, macOS Sonoma, and macOS Tahoe before releases 15.7.8, 14.8.8, and 26.6 respectively, and all versions of tvOS, visionOS, and watchOS before 26.6 are susceptible. The fix is included in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The EPSS score is reported as < 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.8 denotes high severity. Based on the description, an attacker would need to deliver a specially crafted texture to an application that processes textures; no remote or network‑based attack vector is indicated.

Generated by OpenCVE AI on August 4, 2026 at 13:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the OS update that contains the integer‑overflow fix (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6).
  • If updating is not immediately possible, limit the use of applications that import or render user‑supplied textures to reduce exposure.
  • Monitor system logs for texture‑related crashes to confirm that the mitigation is effective.

Generated by OpenCVE AI on August 4, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow Exploit Causing App Crash via Malicious Texture

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Exploit Causing App Crash via Malicious Texture
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:50:36.126Z

Reserved: 2026-05-01T22:46:27.819Z

Link: CVE-2026-43780

cve-icon Vulnrichment

Updated: 2026-07-28T14:50:11.398Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:02.403

Modified: 2026-07-28T19:44:50.557

Link: CVE-2026-43780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound