Description
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A bounds‑checking failure in the image parsing subsystem of Apple operating systems causes a memory corruption flaw. The flaw, identified as a buffer overrun (CWE‑119), can be triggered by a maliciously crafted image. When the parser processes such an image, it corrupts memory and typically crashes the image‑processing component, leading to a denial‑of‑service to the affected application or, if the crash propagates, to the entire system.

Affected Systems

Apple iOS versions older than 18.7.10, iPadOS versions older than 18.7.10, macOS Golden Gate releases prior to 27, macOS Sequoia prior to 15.7.8, and macOS Sonoma prior to 14.8.8 are vulnerable. Updating any of these systems to the specified fixed releases or newer removes the memory corruption flaw.

Risk and Exploitability

The attack vector is inferred from the description: an adversary can supply a maliciously crafted image through any channel that loads images, such as email attachments, web pages, or in‑app galleries. The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low current exploitation probability; furthermore, the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can trigger a system crash or application termination, it remains a legitimate risk that warrants prompt patching.

Generated by OpenCVE AI on September 20, 2026 at 22:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all Apple iOS devices to iOS 18.7.10 or newer.
  • Update all Apple iPadOS devices to 18.7.10 or newer.
  • Update all Apple macOS devices to macOS Golden Gate 27 or newer, macOS Sequoia 15.7.8 or newer, or macOS Sonoma 14.8.8 or newer.
  • If a device cannot be updated immediately, limit or disable the processing of non‑trusted images in applications until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Apple Image Processing Leading to Denial of Service

Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Apple visionos
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Apple visionos

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Memory Corruption in Image Processing on Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-787

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Memory Corruption in Image Processing on Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-787

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:33:40.962Z

Reserved: 2026-07-20T18:09:35.084Z

Link: CVE-2026-64714

cve-icon Vulnrichment

Updated: 2026-09-16T13:33:01.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:14.067

Modified: 2026-09-16T17:46:41.547

Link: CVE-2026-64714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer