Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.
Published: 2026-07-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow was discovered in image processing routines that, when a maliciously crafted image is handled, allows the execution of arbitrary code. This overflow triggers a failure in input validation that the vendor recently addressed. The weakness falls under CWE-190, and its exploitation can compromise the confidentiality, integrity, and availability of the affected system.

Affected Systems

Apple iOS and iPadOS systems are vulnerable up to version 26.6, while macOS is affected in Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. All newer releases contain the patch.

Risk and Exploitability

The EPSS score is 0.00388 and the vulnerability is not listed in the CISA KEV catalog, so public exploitation data is limited. The CVSS score of 8.8 indicates a high severity. The description confirms that arbitrary code execution is feasible when a malicious image is processed, implying a local or remote attacker could gain control by sending a crafted image through applications that render or preview images. The likely attack vector is inferred to be via image rendering pathways, as the vulnerability is triggered by processing a maliciously crafted image. Because no mitigations are described beyond the patch, the risk of exploitation remains high until the update is applied.

Generated by OpenCVE AI on August 4, 2026 at 23:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS update for all affected Apple devices (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6).
  • On devices that cannot be updated immediately, disable automatic preview or rendering of images from untrusted sources by configuring system or application settings to block or quarantine external image files.
  • Deploy endpoint protection or content filtering solutions that detect and block maliciously crafted images, and monitor vendor advisories for any follow‑up mitigations.

Generated by OpenCVE AI on August 4, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution. An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Image Processing Enables Arbitrary Code Execution on Apple Devices

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Image Processing Leading to Arbitrary Code Execution
Weaknesses CWE-680

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Image Processing Leading to Arbitrary Code Execution
Weaknesses CWE-680

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:47.316Z

Reserved: 2026-05-01T22:46:27.822Z

Link: CVE-2026-43818

cve-icon Vulnrichment

Updated: 2026-07-28T14:34:42.866Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:04.817

Modified: 2026-07-29T05:16:45.630

Link: CVE-2026-43818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound