AI analysis
CVE-2026-64752 is a memory corruption vulnerability in Apple's image processing code that is triggered when a device processes a maliciously crafted image, potentially via vectors such as received messages, email attachments, or web content. Successful exploitation can lead to arbitrary code execution on the affected device, meaning an attacker could run their own code in the context of the image-processing component. The flaw affects iPhones, iPads, Macs, and Apple Vision Pro headsets running operating system versions prior to the fixed releases, and it was remediated by removing the vulnerable code entirely. The fix shipped in iOS 27, iPadOS 27, macOS Golden Gate 27, and visionOS 27 as part of a broader batch of roughly 200 patched vulnerabilities. There is no CVSS score yet, no known public proof of concept, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog.
What to do: Update all Apple devices to iOS 27, iPadOS 27, macOS Golden Gate 27, or visionOS 27 as soon as possible via Settings > General > Software Update, and use MDM to push the update across managed fleets. Until patched, advise users to avoid opening unsolicited images from unknown senders in Messages, Mail, and on the web. Monitor Apple's security advisories and the CISA KEV list for any change in exploitation status.
Affected
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS Golden Gate | versions prior to macOS Golden Gate 27 |
| Apple visionOS | versions prior to visionOS 27 |
Estimated exposure
mass≈1 billion+ devices (all iPhone, iPad, Mac, and Vision Pro units not yet updated to the version 27 OS releases) — Apple's publicly disclosed active device base exceeds 2 billion units across iOS, iPadOS, macOS, and visionOS, and any device running an OS version prior to the 27 releases is potentially vulnerable pending update.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.