{
  "id": 1730537,
  "title": "Apple plugs image-processing hole ripe for spyware abuse",
  "url": "https://urgent.news/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-18T14:56:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031"
  },
  "original_language": "en",
  "account": "Apple has released a series of security updates for its devices including iPhones, iPads, and Macs, addressing multiple vulnerabilities that could potentially be exploited by spyware. The most significant patch is for CVE-2026-65346, an integer overflow bug in Apple's ImageIO framework, which is responsible for decoding image files. This flaw, discovered by Meta's Red Team X, could allow attackers to execute arbitrary code when an affected device processes an image. Vulnerable devices include all iPhones from the iPhone 11 onwards, as well as supported iPad Pro, iPad Air, iPad, and iPad mini models.\n\nApple addressed the issue by implementing improved input validation in its latest updates, released on August 17. Experts strongly recommend users to install these updates as soon as possible. Adam Boynton, a senior enterprise strategy manager at Jamf, highlighted that exploiting this integer overflow vulnerability could enable an attacker to write memory where it shouldn't and gain code execution.\n\nHistorically, image parsing flaws have been used as delivery mechanisms for zero-click spyware, particularly targeting high-value individuals. Notable campaigns such as Operation Triangulation and FORCEDENTRY have utilized zero-click smartphone exploits triggered by malicious files delivered through messaging services, leveraging the trust in Apple's image-processing software.\n\nWhile most of the other vulnerabilities in the iOS 26.6.1 update are in WebKit, another of Apple's frequently targeted frameworks, Boynton also pointed out CVE-2026-65329 as another concerning flaw. This vulnerability, affecting iPhone 11 and later, could allow an attacker to intercept network traffic if they have a privileged network position, bypass IPsec authentication, and intercept traffic. Apple described the flaw as \"rarer and more serious\" for organizations relying on IPSec-based connectivity, stating that it was fixed with improved state management.\n\nAdditionally, Apple released iOS 18.7.10 and iPadOS 18.7.10 for older devices that cannot support iOS 26. The updates also extended to visionOS 26.6.1, although the security update page still lists it as \"coming soon.\"",
  "summary": "Patch batch spans current kit, older iGadgets, Macs, and Vision Pro",
  "key_points": [
    "Apple releases security updates for iPhones, iPads, Macs.",
    "CVE-2026-65346 integer overflow bug in ImageIO framework exploited.",
    "Experts urge immediate installation of updates to prevent spyware abuse."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Apple plugs image-processing hole ripe for spyware abuse",
        "url": "https://urgent.news/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse-1733018",
        "published": "2026-08-18T14:56:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}