Impact
A type‑confusion issue was found in Apple’s image‑processing subsystem. The flaw arises when the system incorrectly interprets data structures during the processing of a maliciously crafted image, leading to a crash or hang. Apple has addressed the issue with improved checks and has fixed it in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The weakness is CWE‑843 and results only in a denial of service, without compromising confidentiality or integrity.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are impacted. The vulnerability was fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Devices running earlier versions remain vulnerable.
Risk and Exploitability
The CVSS score is 5.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could deliver a malicious image through a web page, email attachment, or other vector. Even if exploitation is unlikely, the denial of service can disrupt availability for services that require high uptime.
OpenCVE Enrichment