EX-ARRR: Sailing the 0-click Seas
Apple faces a zero-click security threat due to a parser bug in its EXR image format decoder. This bug allows attackers to overwrite 800 kilobytes of memory without any user interaction. Apple's EXR decoder allocates a buffer for RGB images but writes RGBA data, causing a four-byte overrun per pixel. The overflow contains attacker-controlled values, making it a serious zero-click vulnerability. The format is rarely scrutinized, making it an ideal target for attackers.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.