Description
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient checks during image processing, allowing a crafted image to trigger a crash or force the system to hang, resulting in a denial‑of‑service. The primary impact is loss of availability for applications that handle images, potentially affecting user experience and critical services that rely on photo processing. The weakness is related to improper input validation that permits a malicious image to exploit internal buffer handling.

Affected Systems

Apple iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 are the only versions known to contain the fix, while earlier releases remain affected. Devices running any of the affected operating systems without the latest patch are vulnerable to this denial‑of‑service attack. Management of these systems should include applying the latest OS update across all devices in the fleet.

Risk and Exploitability

Since the CVSS and EPSS scores are not available, the exact severity and exploitation probability cannot be stated, but the DoS nature of the issue suggests it could be leveraged to disrupt user operations. The likely attack vector is the processing of a maliciously crafted image, which may be delivered via network channels, email attachments, or native applications that automatically import images. The comment that the vulnerability is fixed in the mentioned updates indicates that current versions mitigate the risk, but no known exploitation records or CISA KEV listing suggest limited active exploitation at present.

Generated by OpenCVE AI on August 17, 2026 at 23:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 update from Apple Software Update or the Apple website.
  • Restart the device after the update to ensure all components are refreshed.
  • If a device is unable to receive the latest update, contact Apple Support to resolve update delivery issues.

Generated by OpenCVE AI on August 17, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Image Processing in Apple iOS, iPadOS, and macOS
Weaknesses CWE-787

Mon, 17 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:31:20.751Z

Reserved: 2026-07-22T00:45:50.324Z

Link: CVE-2026-65347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:25.390

Modified: 2026-08-17T22:17:25.390

Link: CVE-2026-65347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:00:05Z

Weaknesses