Description
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.
Published: 2026-08-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Update
AI Analysis

Impact

The flaw arises from insufficient validation when processing image data. Because the system performs inadequate checks, a maliciously crafted image can trigger a crash or hang, resulting in a denial‑of‑service that disables applications handling images, such as Photos, media libraries, or third‑party viewers. The weakness corresponds to an improper input validation issue (CWE‑400).

Affected Systems

Apple iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 contain the fix, while earlier releases remain affected. Devices running any of these operating systems without the latest patch are vulnerable to a denial‑of‑service attack during image processing. Management of these systems should include applying the most current OS update across all devices in the fleet.

Risk and Exploitability

Since the CVSS score is 6.5 and the EPSS score is less than 1%, the severity is medium and the probability of exploitation is low. The vulnerability remains a denial‑of‑service issue that can cause the system to crash or hang when processing a maliciously crafted image, as indicated by the weak input validation (CWE‑400). Management of these systems should consider that the exploit is likely to be delivered via image processing in applications that accept user images, such as photos, media libraries, or file pickers. The lack of listing in the CISA KEV catalog and the low EPSS score suggest no widespread active exploitation at present, but the DoS impact warrants timely patching.

Generated by OpenCVE AI on September 21, 2026 at 06:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, or watchOS 27 update from Apple Software Update or the Apple website.
  • Restart the device after the update to ensure all components are refreshed.
  • If a device is unable to receive the latest update, contact Apple Support to resolve update delivery issues.

Generated by OpenCVE AI on September 21, 2026 at 06:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Image Processing in Apple iOS, iPadOS, and macOS

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service. The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.
References

Tue, 18 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Image Processing in Apple iOS, iPadOS, and macOS

Tue, 18 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 18 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Image Processing in Apple iOS, iPadOS, and macOS
Weaknesses CWE-787

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Image Processing in Apple iOS, iPadOS, and macOS
Weaknesses CWE-787

Mon, 17 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:51:13.856Z

Reserved: 2026-07-22T00:45:50.324Z

Link: CVE-2026-65347

cve-icon Vulnrichment

Updated: 2026-08-18T13:13:24.237Z

cve-icon NVD

Status : Modified

Published: 2026-08-17T22:17:25.390

Modified: 2026-09-14T21:17:19.703

Link: CVE-2026-65347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:15:10Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption