Impact
The vulnerability arises when the operating system decodes a maliciously crafted image, leading to memory corruption. The corruption can affect the process handling the image, potentially causing a crash or allowing an attacker to execute arbitrary code within that process. This weakness stems from improper handling of image data boundaries and is classified as CWE-119.
Affected Systems
Apple iOS versions 18.7.10 and 26.6, iPadOS 18.7.10 and 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are patched in those releases; all earlier releases of the listed operating systems are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact and high exploitability. The EPSS score is less than 1%, and the vulnerability is not in the CISA KEV catalog, suggesting that documented exploitation is currently limited. The attack vector is inferred to be a malicious image that the operating system processes; for example, opening a file, viewing a picture in an email or messaging client, or loading a graphic via a web interface.
OpenCVE Enrichment