Impact
An integer overflow was addressed with improved input validation in Apple’s image processing routines, which is now fixed in iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. The flaw can be triggered by a maliciously crafted image and may lead to arbitrary code execution. This CWE‑190 weakness threatens confidentiality, integrity, and availability when an attacker can deliver a crafted image to the victim.
Affected Systems
Apple iOS and iPadOS systems are vulnerable up to version 26.6, while macOS is affected in Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6. All newer releases contain the patch.
Risk and Exploitability
The EPSS score is 0.00388 and the vulnerability is not listed in the CISA KEV catalog, so public exploitation data is limited. The CVSS score of 8.8 indicates a high severity. The description confirms that arbitrary code execution is feasible when a malicious image is processed, implying a local or remote attacker could gain control by sending a crafted image through applications that render or preview images. The likely attack vector is inferred to be via image rendering pathways, as the vulnerability is triggered by processing a maliciously crafted image. Because no mitigations are described beyond the patch, the risk of exploitation remains high until the update is applied.
OpenCVE Enrichment