Impact
The vulnerability arises from insufficient checks during image processing, allowing a crafted image to trigger a crash or force the system to hang, resulting in a denial‑of‑service. The primary impact is loss of availability for applications that handle images, potentially affecting user experience and critical services that rely on photo processing. The weakness is related to improper input validation that permits a malicious image to exploit internal buffer handling.
Affected Systems
Apple iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 are the only versions known to contain the fix, while earlier releases remain affected. Devices running any of the affected operating systems without the latest patch are vulnerable to this denial‑of‑service attack. Management of these systems should include applying the latest OS update across all devices in the fleet.
Risk and Exploitability
Since the CVSS score is 6.5 and the EPSS score is less than 1%, the severity is medium and the probability of exploitation is low. The vulnerability remains a denial‑of‑service issue that can cause the system to crash or hang when processing a maliciously crafted image, as indicated by the weak input validation (CWE‑400). Management of these systems should consider that the exploit is likely to be delivered via image processing in applications that accept user images, such as photos, media libraries, or file pickers. The lack of listing in the CISA KEV catalog and the low EPSS score suggest no widespread active exploitation at present, but the DoS impact warrants timely patching.
OpenCVE Enrichment