High severity8.8NVD Advisory· Published Aug 17, 2026· Updated Sep 14, 2026
CVE-2026-65346
CVE-2026-65346
Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.
Affected products
10- Range: 26.6.1
26.6.1+ 1 more
- (no CPE)range: 26.6.1
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <26.6.1
- Range: 15.8
- Range: 26.6.2
- Range: 27
- Range: 27
- Range: 27
Patches
Vulnerability mechanics
References
6- support.apple.com/en-us/148281nvdRelease NotesVendor Advisory
- support.apple.com/en-us/148282nvdRelease NotesVendor Advisory
- support.apple.com/en-us/149036nvd
- support.apple.com/en-us/149037nvd
- support.apple.com/en-us/149038nvd
- support.apple.com/en-us/149043nvd
News mentions
8- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksThe Hacker News · Sep 21, 2026
- Apple Updates Everything, (Mon, Sep 14th)SANS Internet Storm Center · Sep 14, 2026
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- Apple plugs image-processing hole ripe for spyware abuseThe Register Security · Aug 18, 2026
- Apple fixes another image-processing flaw that could allow code executionMalwarebytes Labs · Aug 18, 2026
- Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOSCyber Security News · Aug 18, 2026
- Apple iOS: 25 Vulnerabilities Patched in Same-Day Disclosure BatchVypr Intelligence · Aug 17, 2026
- Apple Patches iOS and macOS, (Mon, Aug 17th)SANS Internet Storm Center · Aug 17, 2026