
Apple has rolled out security updates for iPhones, iPads and Macs addressing a potentially dangerous vulnerability in its image-processing framework – the kind of flaw that has historically been useful to makers of sophisticated mobile spyware.
CVE-2026-65346 is an integer-overflow vulnerability in ImageIO, an Apple framework responsible for reading and processing image data.
The vulnerability affects Apple's ImageIO framework across its entire product lineup and could allow arbitrary code execution when a vulnerable device processes a maliciously crafted image.
Apple patched the issue in updates released Aug. 17, including iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and iOS 18.7.10 and iPadOS 18.7.10.
While Apple has not said the vulnerability has been exploited in the wild, its location and potential impact make it noteworthy. Image-processing vulnerabilities have been used as components of earlier zero-click spyware attacks, where victims can be compromised without opening a malicious attachment or knowingly interacting with an attacker.
According to Apple's security advisory, processing an image on a vulnerable device may lead to arbitrary code execution. Apple says it addressed the vulnerability through improved input validation. The company credits Nik Tsytsarkin of Meta Red Team X with reporting it.
The vulnerability affects iPhone 11 and later, along with iPad Pro, iPad Air, iPad and iPad mini models. It also affects macOS Tahoe.
There is no evidence disclosed so far that CVE-2026-65346 has been used to deploy spyware.
However, researchers are paying attention because vulnerabilities in image-processing components have been exploited in highly sophisticated attacks in the past.
One of the best-known examples is FORCEDENTRY, an exploit used to deliver NSO Group's Pegasus spyware. The attack exploited Apple's image-processing technology and allowed malicious content delivered through iMessage to compromise devices without victims clicking a link.
Another sophisticated campaign, Operation Triangulation, also relied on zero-click techniques delivered through Apple's messaging ecosystem.
These attacks demonstrate why vulnerabilities in components that automatically process incoming content are invaluable to spyware operators.
It’s not necessary that a victim fall for a phishing message. In a zero-click attack, receiving specially crafted content may be enough to start an exploitation chain.
While the vulnerability has characteristics that could make it useful in sophisticated attacks, it isn’t a zero-day known to be under active attack – i.e. Apple doesn’t say it has actually been exploited.
But that doesn’t mean attackers aren’t doing so now. So it’s advisable to apply this patch soon.
CVE-2026-65346 isn't the only security problem addressed in Apple's latest updates.
The patched vulnerabilities affect components including Audio, ImageIO, IOGPUFamily, Kernel, Telephony and WebKit. The consequences of the issues could range from information disclosure and crashes to memory corruption and code execution.
Another notable issue is CVE-2026-65329, an authentication vulnerability in Apple's Telephony component.
According to Apple, an attacker in a privileged network position could bypass IPsec authentication and intercept network traffic. Apple addressed the vulnerability with improved state management.
The update also includes multiple fixes for WebKit, the browser engine powering Safari and web content across Apple's platforms.
Apple additionally released iOS 18.7.10 and iPadOS 18.7.10 for older hardware unable to run iOS 26, including devices such as the iPhone XS, XS Max and XR.
For most people, the key response is straightforward: install Apple's latest security updates promptly.
On an iPhone or iPad, go to Settings > General > Software Update and install the latest version available for your device.
Mac users can check System Settings > General > Software Update.
Users should also consider these precautions:
CVE-2026-65346 is a reminder that something as ordinary as an image can become an attack surface.
There is currently no public evidence that attackers have exploited the vulnerability to deploy spyware, and users shouldn't assume that every malicious image could compromise an iPhone. But previous campaigns involving mercenary spyware have demonstrated why vulnerabilities in automatically processed content deserve attention.
Apple has released the fix. Installing it is the simplest way to remove the risk posed by this particular vulnerability.
You may also like:
macOS ‘Screen Sharing’ flaw exploited for crypto-mining
WhatsApp detects new spyware activity from Israel’s NSO Group despite court order
Zero-day phone hacks: how spyware slips into your device before anyone knows
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts