Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

A memory corruption flaw in Apple operating systems was addressed by removing the vulnerable code paths. Processing a maliciously crafted image can lead to arbitrary code execution, allowing an attacker to control the affected device. The vulnerability stems from improper handling of image data, resulting in memory corruption that can be leveraged to jump to attacker supplied code.

Affected Systems

Apple iOS and iPadOS, Apple macOS Golden Gate, and Apple visionOS devices running versions prior to 27 are affected. The issue was fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, and visionOS 27.

Risk and Exploitability

The CVSS score is not publicly disclosed, and the EPSS score is unavailable, but the exploitability is high because arbitrary code execution can be achieved by feeding a crafted image to the system. The likely attack vector would involve an attacker providing a malicious image through a user‑initiated action such as opening a file, viewing a link, or installing an app that manipulates image data. The lack of a KEV listing suggests but the potential for exploitation remains significant given the nature of the flaw.

Generated by OpenCVE AI on September 15, 2026 at 09:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OS updates that contain the fix for iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27.
  • Ensure that all applications that handle image data are updated to their latest versions and run under the recommended sandboxed environment to limit the impact of any remaining image processing bugs.
  • Avoid opening or rendering images from untrusted sources, and use content‑filtering tools to block malicious image files whenever possible.

Generated by OpenCVE AI on September 15, 2026 at 09:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Allowing Arbitrary Code Execution via Malicious Image on Apple OS
Weaknesses CWE-122
CWE-125

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.
References

Subscriptions

Apple Ios And Ipados Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:18.514Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64752

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:14.770

Modified: 2026-09-14T21:17:14.770

Link: CVE-2026-64752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:45:17Z

Weaknesses