Apple rushes out a fix for a zero-click ImageIO bug

Started by OfficialLuca92, Today at 10:00 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Apple rushes out a fix for a zero-click ImageIO bug   Views(Read 13 times)
Active members in this topic:
OfficialLuca92(1)

OfficialLuca92

Apple pushed out iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 this week to close a hole in ImageIO, the framework every Apple device uses to decode images. The flaw is tracked as CVE-2026-65346 and it is an integer overflow, meaning a crafted image can push a calculation past the memory Apple set aside for it, and whoever crafted that image gets to decide what happens with the overflow. Apple credits Nik Tsytsarkin of Meta's Red Team X with finding it, which is a slightly odd but increasingly normal situation where one Big Tech company's internal offense team is quietly making another one's products safer.

What makes this one worth patching today rather than next weekend is where ImageIO sits in the stack. It runs underneath Messages, Mail, Safari and basically any app that renders a picture, so the vulnerable code executes wherever an image gets drawn on screen rather than inside some app you could just avoid using. Apple says it fixed the issue with improved input validation, which is the usual polite phrasing for we added bounds checks that should have been there already. There is no public confirmation yet that this specific bug was used in the wild, but Apple's advisory language and the researcher credit both point toward a bug that was found before attackers got there rather than after.

The update is not a solo fix either. It bundles 27 to 29 other patches depending on which count you use, spanning Audio, Kernel, Telephony and a long list of WebKit issues. One of the more interesting side items is CVE-2026-65329 in Telephony, which a group of researchers at Ruhr University Bochum found and which lets an attacker in a privileged network position bypass IPSec authentication and snoop on traffic, a very different kind of threat model from the drive by image attack but bundled into the same release.

History is doing a lot of the heavy lifting here in terms of urgency. Image parsing bugs in ImageIO have shown up before as the delivery mechanism for some very sophisticated, very targeted zero-click spyware campaigns aimed at journalists, executives and activists. Nobody is saying this particular bug was weaponized that way, but the pattern is familiar enough that security researchers are treating the release as more than routine housekeeping.

For anyone running an iPhone 11 or later, or a recent iPad Pro, Air, standard iPad or iPad mini, the update is available now and installing it does not require anything more exotic than opening Settings and tapping update. Given how boring and unglamorous image parsing sounds compared to something like a kernel exploit, it is worth remembering that boring plumbing breaking is exactly how the scary stuff usually starts.


Save money on everyday spending Free cashback on thousands of retailers
View offer