Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

A memory corruption flaw in Apple operating systems was addressed by removing the vulnerable code paths. Processing a maliciously crafted image can lead to arbitrary code execution, allowing an attacker to control the affected device. The vulnerability stems from improper handling of image data, resulting in memory corruption that can be leveraged to jump to attacker supplied code.

Affected Systems

Apple iOS and iPadOS, Apple macOS Golden Gate, and Apple visionOS devices running versions prior to 27 are affected. The issue was fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, and visionOS 27.

Risk and Exploitability

The CVSS score is 7.3, and the EPSS score is <1%, but the exploitability is high because arbitrary code execution can be achieved by feeding a crafted image to the system. The likely attack vector would involve an attackerated action such as opening a file, viewing a link, or installing an app that manipulates image data. The lack of a KEV listing suggests but the potential for exploitation remains significant given the nature of the flaw.

Generated by OpenCVE AI on September 20, 2026 at 19:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OS updates that contain the fix for iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27.
  • Ensure that all applications that handle image data are updated to their latest versions and run under the recommended sandboxed environment to limit the impact of any remaining image processing bugs.
  • Avoid opening or rendering images from untrusted sources, and use content‑filtering tools to block malicious image files whenever possible.

Generated by OpenCVE AI on September 20, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Image Processing Causing Arbitrary Code Execution in Apple OSes

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption Allowing Arbitrary Code Execution via Malicious Image on Apple OS
Weaknesses CWE-122
CWE-125

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Allowing Arbitrary Code Execution via Malicious Image on Apple OS
Weaknesses CWE-122
CWE-125

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:56:10.635Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64752

cve-icon Vulnrichment

Updated: 2026-09-15T13:55:03.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:14.770

Modified: 2026-09-16T04:18:38.373

Link: CVE-2026-64752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:00:04Z

Weaknesses