Impact
The flaw arises from insufficient validation when processing image data. Because the system performs inadequate checks, a maliciously crafted image can trigger a crash or hang, resulting in a denial‑of‑service that disables applications handling images, such as Photos, media libraries, or third‑party viewers. The weakness corresponds to an improper input validation issue (CWE‑400).
Affected Systems
Apple iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 contain the fix, while earlier releases remain affected. Devices running any of these operating systems without the latest patch are vulnerable to a denial‑of‑service attack during image processing. Management of these systems should include applying the most current OS update across all devices in the fleet.
Risk and Exploitability
Since the CVSS score is 6.5 and the EPSS score is less than 1%, the severity is medium and the probability of exploitation is low. The vulnerability remains a denial‑of‑service issue that can cause the system to crash or hang when processing a maliciously crafted image, as indicated by the weak input validation (CWE‑400). Management of these systems should consider that the exploit is likely to be delivered via image processing in applications that accept user images, such as photos, media libraries, or file pickers. The lack of listing in the CISA KEV catalog and the low EPSS score suggest no widespread active exploitation at present, but the DoS impact warrants timely patching.
OpenCVE Enrichment