4 min read

Update your iPhone and Mac! Apple patches image flaw with spyware potential

Filip TRUȚĂ

August 19, 2026

Update your iPhone and Mac! Apple patches image flaw with spyware potential

Apple has rolled out security updates for iPhones, iPads and Macs addressing a potentially dangerous vulnerability in its image-processing framework – the kind of flaw that has historically been useful to makers of sophisticated mobile spyware.

Key takeaways

  • Apple patched an integer-overflow vulnerability in its ImageIO image-processing framework
  • Processing a malicious image could allow arbitrary code execution on an affected device
  • Image-processing vulnerabilities have played a role in sophisticated zero-click spyware campaigns
  • The flaw was reported by Nik Tsytsarkin of Meta's Red Team X
  • There is currently no public confirmation that CVE-2026-65346 has been exploited in real-world spyware attacks
  • Apple users are advised to install the latest OS updates as soon as possible

An image-processing vulnerability

CVE-2026-65346 is an integer-overflow vulnerability in ImageIO, an Apple framework responsible for reading and processing image data.

The vulnerability affects Apple's ImageIO framework across its entire product lineup and could allow arbitrary code execution when a vulnerable device processes a maliciously crafted image.

Apple patched the issue in updates released Aug. 17, including iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, and iOS 18.7.10 and iPadOS 18.7.10.

While Apple has not said the vulnerability has been exploited in the wild, its location and potential impact make it noteworthy. Image-processing vulnerabilities have been used as components of earlier zero-click spyware attacks, where victims can be compromised without opening a malicious attachment or knowingly interacting with an attacker.

According to Apple's security advisory, processing an image on a vulnerable device may lead to arbitrary code execution. Apple says it addressed the vulnerability through improved input validation. The company credits Nik Tsytsarkin of Meta Red Team X with reporting it.

The vulnerability affects iPhone 11 and later, along with iPad Pro, iPad Air, iPad and iPad mini models. It also affects macOS Tahoe.

Can be leveraged in spyware attacks

There is no evidence disclosed so far that CVE-2026-65346 has been used to deploy spyware.

However, researchers are paying attention because vulnerabilities in image-processing components have been exploited in highly sophisticated attacks in the past.

One of the best-known examples is FORCEDENTRY, an exploit used to deliver NSO Group's Pegasus spyware. The attack exploited Apple's image-processing technology and allowed malicious content delivered through iMessage to compromise devices without victims clicking a link.

Another sophisticated campaign, Operation Triangulation, also relied on zero-click techniques delivered through Apple's messaging ecosystem.

These attacks demonstrate why vulnerabilities in components that automatically process incoming content are invaluable to spyware operators.

It’s not necessary that a victim fall for a phishing message. In a zero-click attack, receiving specially crafted content may be enough to start an exploitation chain.

Apple hasn't reported active exploitation

While the vulnerability has characteristics that could make it useful in sophisticated attacks, it isn’t a zero-day known to be under active attack – i.e. Apple doesn’t say it has actually been exploited.

But that doesn’t mean attackers aren’t doing so now. So it’s advisable to apply this patch soon.

Apple's update fixes more than ImageIO

CVE-2026-65346 isn't the only security problem addressed in Apple's latest updates.

The patched vulnerabilities affect components including Audio, ImageIO, IOGPUFamily, Kernel, Telephony and WebKit. The consequences of the issues could range from information disclosure and crashes to memory corruption and code execution.

Another notable issue is CVE-2026-65329, an authentication vulnerability in Apple's Telephony component.

According to Apple, an attacker in a privileged network position could bypass IPsec authentication and intercept network traffic. Apple addressed the vulnerability with improved state management.

The update also includes multiple fixes for WebKit, the browser engine powering Safari and web content across Apple's platforms.

Apple additionally released iOS 18.7.10 and iPadOS 18.7.10 for older hardware unable to run iOS 26, including devices such as the iPhone XS, XS Max and XR.

How Apple users can stay safe

For most people, the key response is straightforward: install Apple's latest security updates promptly.

On an iPhone or iPad, go to Settings > General > Software Update and install the latest version available for your device.

Mac users can check System Settings > General > Software Update.

Users should also consider these precautions:

  • Enable automatic updates. Keeping automatic updates enabled reduces the time your device remains exposed after security patches become available.
  • Don't postpone security updates. Vulnerabilities become much more useful to attackers once patches reveal that a weakness exists.
  • Keep messaging and browser apps updated. These applications often process content from potentially untrusted sources.
  • Be alert to unusual device behavior. Unexpected crashes, unexplained battery drain or other anomalies aren't proof of spyware, but persistent suspicious behavior warrants investigation.
  • High-risk users should consider Lockdown Mode. Apple provides Lockdown Mode for people who believe they may be targeted by highly sophisticated digital threats.
  • Run an independent security solution on your iPhone, iPad or Mac to add another layer of security.

CVE-2026-65346 is a reminder that something as ordinary as an image can become an attack surface.

There is currently no public evidence that attackers have exploited the vulnerability to deploy spyware, and users shouldn't assume that every malicious image could compromise an iPhone. But previous campaigns involving mercenary spyware have demonstrated why vulnerabilities in automatically processed content deserve attention.

Apple has released the fix. Installing it is the simplest way to remove the risk posed by this particular vulnerability.

You may also like:

macOS ‘Screen Sharing’ flaw exploited for crypto-mining

WhatsApp detects new spyware activity from Israel’s NSO Group despite court order

Zero-day phone hacks: how spyware slips into your device before anyone knows

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader