ZeroHour

CVE-2026-65395

mass

Out-of-Bounds Write in Apple Image Processing Affects iOS, macOS, tvOS, visionOS

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-65395 is an out-of-bounds write vulnerability in Apple's image processing code that was fixed with improved bounds checking; processing a maliciously crafted image can corrupt memory on an unpatched device. The flaw is triggered simply by an application parsing a hostile image file, which in practice means a victim could be affected by receiving or previewing an image in apps such as Messages, Mail, or a web page. Successful exploitation of memory corruption of this type can plausibly lead to application crashes or arbitrary code execution within the parsing process, though Apple has not stated that it has been exploited. Affected users are those on iOS/iPadOS versions prior to 26.7 (and not on 27), macOS Sequoia prior to 15.8, macOS Tahoe prior to 26.7, macOS Golden Gate prior to 27, tvOS prior to 27, and visionOS prior to 27. The issue has no CVSS score yet, is not in the CISA KEV catalog, and no public proof of concept is known.

What to do: Update all Apple devices to the fixed releases: iOS/iPadOS 26.7 or 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, and visionOS 27; use MDM to push these updates across managed fleets and audit for devices still on older OS builds. Because the flaw can trigger during image preview, users should treat unsolicited images in Messages, Mail, and on the web with caution until patched. Monitor Apple security advisories and crash logs for signs of image-parsing crashes, and revisit KEV/CVSS status once scored.

Affected
Apple iOSversions prior to iOS 26.7 and prior to iOS 27
Apple iPadOSversions prior to iPadOS 26.7 and prior to iPadOS 27
Apple macOS Sequoiaversions prior to 15.8
Apple macOS Tahoeversions prior to 26.7
Apple macOS Golden Gateversions prior to 27
Apple tvOSversions prior to 27
Apple visionOSversions prior to 27
Estimated exposure
mass≈1-2+ billion Apple devices (Apple's active installed base exceeds 2 billion devices) — Apple's publicly disclosed active device installed base is over 2 billion iPhones, iPads, Macs, Apple TVs, and Vision Pros, and unpatched devices running any affected OS version are exposed until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted image may result in memory corruption.

Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.