Apple plugs image-processing hole ripe for spyware abuse
Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
Apple has released a series of security updates for its devices including iPhones, iPads, and Macs, addressing multiple vulnerabilities that could potentially be exploited by spyware. The most significant patch is for CVE-2026-65346, an integer overflow bug in Apple's ImageIO framework, which is responsible for decoding image files.
This flaw, discovered by Meta's Red Team X, could allow attackers to execute arbitrary code when an affected device processes an image. Vulnerable devices include all iPhones from the iPhone 11 onwards, as well as supported iPad Pro, iPad Air, iPad, and iPad mini models.
Apple addressed the issue by implementing improved input validation in its latest updates, released on August 17. Experts strongly recommend users to install these updates as soon as possible. Adam Boynton, a senior enterprise strategy manager at Jamf, highlighted that exploiting this integer overflow vulnerability could enable an attacker to write memory where it shouldn't and gain code execution.
Historically, image parsing flaws have been used as delivery mechanisms for zero-click spyware, particularly targeting high-value individuals. Notable campaigns such as Operation Triangulation and FORCEDENTRY have utilized zero-click smartphone exploits triggered by malicious files delivered through messaging services, leveraging the trust in Apple's image-processing software.
While most of the other vulnerabilities in the iOS 26.6.1 update are in WebKit, another of Apple's frequently targeted frameworks, Boynton also pointed out CVE-2026-65329 as another concerning flaw. This vulnerability, affecting iPhone 11 and later, could allow an attacker to intercept network traffic if they have a privileged network position, bypass IPsec authentication, and intercept traffic.
Apple described the flaw as "rarer and more serious" for organizations relying on IPSec-based connectivity, stating that it was fixed with improved state management.
Additionally, Apple released iOS 18.7.10 and iPadOS 18.7.10 for older devices that cannot support iOS 26. The updates also extended to visionOS 26.6.1, although the security update page still lists it as "coming soon."
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Apple plugs image-processing hole ripe for spyware abuse theregister.com