Apple plugs image-processing hole ripe for spyware abuse

← Back to the feed

Apple plugs image-processing hole ripe for spyware abuse

The Register · 3 hours ago

Apple has released a batch of security updates for iPhones, iPads, Macs and Vision Pro headsets, including a fix for a flaw that experts say resembles vulnerabilities previously exploited by commercial spyware. The most significant patch addresses CVE-2026-65346, an integer-overflow bug in Apple's ImageIO framework, which handles image file parsing and could allow attackers to execute arbitrary code simply by having a device process a malicious image. Because such flaws have historically been used in zero-click spyware attacks against journalists, executives and diplomats, security specialists are urging users to install the updates without delay.

The bug was discovered by Nik Tsytsarkin of Meta's Red Team X and affects macOS Tahoe, iPhone 11 and later, and supported iPad models; Apple fixed it through improved input validation in updates released on 17 August. Experts drew parallels with past campaigns such as Operation Triangulation and the FORCEDENTRY exploit used to deliver NSO Group's Pegasus spyware, though Apple has not confirmed whether this particular bug was actively exploited. The update batch also fixes CVE-2026-65329, a Telephony component flaw that could let a network-positioned attacker bypass IPsec authentication and intercept traffic, plus numerous WebKit issues. Apple additionally issued iOS 18.7.10 and iPadOS 18.7.10 for older devices like the iPhone XS and XR, and visionOS 26.6.1, though full details for the latter were not yet published.

  • Apple patched an ImageIO flaw resembling past spyware exploit techniques
  • Bug affects iPhone 11+, supported iPads and macOS Tahoe
  • Separate Telephony flaw could let attackers intercept network traffic
  • Older devices also received updates via iOS/iPadOS 18.7.10

Gadgets Technology

Read the full article at the source →