Impact
An integer overflow was identified during image processing in Apple operating systems, and the flaw was corrected with improved input validation. The overflow can be triggered by processing a carefully crafted image file, allowing an attacker to execute arbitrary code with the privileges of the image‑processing application. This represents a classic integer overflow weakness that can be abused to compromise the confidentiality, integrity, and availability of the affected device.
Affected Systems
Apple iOS and iPadOS are affected through the 26.6.1 release, while macOS Tahoe is affected in its 26.6.2 update. Users running earlier versions of these operating systems are therefore vulnerable until they apply the specified updates.
Risk and Exploitability
No CVSS score is documented for this issue and the EPSS score was not provided, so the current estimation of exploitation probability remains unknown. The flaw is listed as not present in the CISA KEV catalog, suggesting no confirmed publicly available exploits at the time of analysis. Based on the description, the most likely attack path involves an untrusted image file being processed locally on the device; however, the vulnerability could be triggered by any mechanism that delivers image data to the affected subsystems. Because the vulnerability is tied to input validation, it would require the attacker to supply a precisely crafted image and access to a system that accepts such files, indicating a local or remote file‑submission scenario.
OpenCVE Enrichment