Security· August 18, 2026 at 02:56 p.m.
Apple Addresses Image Processing Vulnerability Potentially Used for Spyware Delivery
Key takeaways
- Apple released patches to address vulnerabilities
- CVE-2026-65346 is an integer-overflow bug in ImageIO
- Experts advise users to install the August 17 updates
Apple has released a series of patches to address vulnerabilities in its devices, including an image-processing flaw (CVE-2026-65346) discovered by Meta's Red Team X. This integer-overflow bug could allow arbitrary code execution when processing images on affected devices such as macOS Tahoe, iPhone 11 and later, and certain iPad models. Experts urge users to install the August 17 updates promptly. Adam Boynton, senior enterprise strategy manager at Jamf, stated that this image parsing flaw has historically been a delivery mechanism for zero-click spyware targeting high-value individuals.