EX-ARRR: Sailing the 0-click Seas
Researcher reports a zero-click heap overflow in Apple's OpenEXR decoder, triggered when iMessage parses an image.
A researcher published a write-up of a zero-click heap overflow in Apple's OpenEXR decoder, libAppleEXR, which ImageIO uses to parse EXR images. The destination buffer is sized for RGB while the interleave path writes an extra alpha channel, so mostly attacker-controlled pixel data spills into adjacent heap memory. The author says an iMessage carrying the image is decoded immediately by a privileged daemon, with no tap, and that they reproduced the overflow on a real iPad. The excerpt does not name a CVE, affected versions, or a patch.
78