Impact
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27. Processing an image may lead to arbitrary code execution, potentially compromising confidentiality, integrity, and availability of the device.
Affected Systems
Apple iOS and iPadOS are affected through the 26.6.1 release; macOS Sequoia through 15.8; macOS Tahoe through 26.6.2; tvOS 27; visionOS 27; and watchOS 27. Users running earlier versions of these operating systems are therefore vulnerable until they apply the specified updates.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is < 1%, so the current estimation of exploitation probability remains low but nonzero. The flaw is listed as not present in the CISA KEV catalog, suggesting no confirmed publicly available exploits at the time of analysis. Based on the description, the most likely attack path involves an untrusted image file being processed locally on the device; however, the vulnerability could be triggered by any mechanism that delivers image data to the affected subsystems. Because the vulnerability is tied to input validation, it would require the attacker to supply a precisely crafted image and access to a system that accepts such files, indicating a local or remote file‑submission scenario.
OpenCVE Enrichment