Impact
A type‑confusion flaw exists in Apple’s image‑processing subsystem. When the decoder misinterprets data structures while handling a maliciously crafted image file, it triggers a crash or hangs the application or system. The weakness is CWE‑843 and results solely in a denial of service, with no compromise of confidentiality or integrity.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are impacted. The vulnerability was fixed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier versions remain vulnerable.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could deliver a malicious image through a web page, email attachment, or other vector. Even if exploitation is unlikely, the denial of service can disrupt availability for services that require high uptime.
OpenCVE Enrichment