Home Technology Apple plugs image-processing hole ripe for spyware abuse
Technology

Apple plugs image-processing hole ripe for spyware abuse

Apple plugs image-processing hole ripe for spyware abuse
Key Points

Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files. Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image.

Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files. Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image. The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models. Apple said it addressed the flaw with improved input validation, and experts urged users to install the August 17 updates as soon as possible. Adam Boynton, senior enterprise strategy manager at Jamf, said: "iOS 26.6.1's standout fix is CVE-2026-65346, an integer overflow in ImageIO. This is Apple's system framework for decoding images and exploiting it could allow an attacker to write memory where they shouldn't and gain code execution. "Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals." Several of the most damaging spyware campaigns in recent years have used zero-click smartphone exploits triggered by malicious files delivered through messaging services. Operation Triangulation, which Russia's FSB claimed was the work of the NSA, used such tactics. So did FORCEDENTRY, an exploit used to deliver NSO Group's Pegasus spyware through Apple's image-processing software. The Register asked Apple if it was aware of CVE-2026-65346 being used in spyware campaigns, but it did not immediately respond. Most of the other vulnerabilities in the iOS 26.6.1 update are, surprise, surprise, in WebKit – arguably Apple's most pummeled framework. Boynton also highlighted CVE-2026-65329 as one of the batch's more concerning flaws. Affecting iPhone 11 and later, the vulnerability lies in Apple's Telephony component and could allow an attacker to intercept network traffic. Apple said an attacker would need a privileged network position to exploit the bug, bypass IPsec authentication, and intercept traffic. Boynton described the flaw as "rarer and more serious for organisations relying on IPSec-based connectivity." Cupertino put it down to an authentication issue that it fixed with improved state management. The iGiant also released iOS 18.7.10 and iPadOS 18.7.10 for older devices that cannot run iOS 26, including the iPhone XS, XS Max, and XR. Monday's releases extended to visionOS 26.6.1 as well, although Apple's security updates page still lists the details as "coming soon." ® [Image text:] THU 5 104 Messages
Apple (ORG) iPhones (ORG) iPads (ORG) Macs (ORG) CVE-2026-65346 (ORG) Nik Tsytsarkin (PERSON) Meta (ORG) Red Team X (ORG) Tahoe (LOCATION) iPhone 11 (ORG) iPad Air (ORG) iPad (ORG) Adam Boynton (PERSON) Jamf (ORG) Operation Triangulation (ORG)
Originally published by The Register Read original →