ZeroHour

CVE-2026-64752

mass

Image Processing Memory Corruption in Apple iOS, iPadOS, macOS, visionOS

CVSS 3.1
7.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-64752 is a memory corruption vulnerability in Apple's image processing code that is triggered when a device processes a maliciously crafted image, potentially via vectors such as received messages, email attachments, or web content. Successful exploitation can lead to arbitrary code execution on the affected device, meaning an attacker could run their own code in the context of the image-processing component. The flaw affects iPhones, iPads, Macs, and Apple Vision Pro headsets running operating system versions prior to the fixed releases, and it was remediated by removing the vulnerable code entirely. The fix shipped in iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27 as part of a broader batch of roughly 200 patched vulnerabilities. There is no CVSS score yet, no known public proof of concept, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Update all Apple devices to iOS 27, iPadOS 27, macOS Golden Gate 27, or visionOS 27 as soon as possible via Settings > General > Software Update, and use MDM to push the update across managed fleets. Until patched, advise users to avoid opening unsolicited images from unknown senders in Messages, Mail, and on the web. Monitor Apple's security advisories and the CISA KEV list for any change in exploitation status.

Affected
Apple iOSversions prior to iOS 27
Apple iPadOSversions prior to iPadOS 27
Apple macOS Golden Gateversions prior to macOS Golden Gate 27
Apple visionOSversions prior to visionOS 27
Estimated exposure
mass≈1 billion+ devices (all iPhone, iPad, Mac, and Vision Pro units not yet updated to the version 27 OS releases) — Apple's publicly disclosed active device base exceeds 2 billion units across iOS, iPadOS, macOS, and visionOS, and any device running an OS version prior to the 27 releases is potentially vulnerable pending update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.

Vendors
apple
Products
ipados, iphone os, macos, visionos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Apple patched a record 200+ vulnerabilities in iOS 27 and macOS Golden Gate 27, including 20 kernel flaws; none exploited in the wild.

Apple's iOS 27 and iPadOS 27 releases fix roughly 126 security flaws, 20 of them in the kernel, while macOS Golden Gate 27 addresses 210 vulnerabilities, about 100 shared with the mobile release. macOS Tahoe 26.7 patches 153 unique CVEs, including 26 kernel defects that could cause memory corruption, privilege escalation, system termination, and information leaks. Notable fixes include CVE-2026-64752, a CoreMedia memory corruption flaw allowing iPhone compromise via a malicious image, and CVE-2022-3437, a heap buffer overflow in Heimdal Samba enabling denial-of-service. Apple states none of the patched flaws are known to be exploited in the wild.