
PEACH
Un cadre d’isolation des locataires
CVE-2026-65346 is an integer overflow vulnerability in Apple's ImageIO framework that allows arbitrary code execution when processing a specially crafted image file. It was discovered by Nik Tsytsarkin of Meta Red Team X and disclosed on August 17, 2026, alongside Apple's security updates. Affected platforms include iOS and iPadOS versions prior to 26.6.1, and macOS Tahoe versions prior to 26.6.2. The vulnerability is estimated as HIGH severity; a formal CVSS score has not yet been published (EPSS: 0.0) (Apple iOS Advisory, Apple macOS Advisory, GitHub Advisory).
The root cause is an integer overflow (CWE-190) in Apple's ImageIO image processing component, triggered when parsing a maliciously crafted image file. Insufficient input validation allows an attacker-controlled value to overflow an integer, potentially corrupting memory in a way that enables arbitrary code execution. The attack vector is local or network-delivered (e.g., via a malicious image sent through messaging, email, or a web page), requiring no authentication — only that the target device processes the crafted image. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Apple iOS Advisory, Apple macOS Advisory).
Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the application processing the image (e.g., a photo viewer, browser, or messaging app). On mobile devices, this could expose sensitive user data, enable installation of malware, or serve as a stepping stone for privilege escalation. The vulnerability affects a broad range of Apple hardware, including iPhone 11 and later, multiple iPad generations, and all Macs running macOS Tahoe prior to 26.6.2 (Apple iOS Advisory, Apple macOS Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. The vulnerability was reported by a researcher at Meta Red Team X, suggesting it was identified through internal security research rather than observed exploitation (GitHub Advisory, Apple iOS Advisory).
Apple has released patches addressing this vulnerability: update to iOS 26.6.1 or iPadOS 26.6.1 for iPhone and iPad devices, and macOS Tahoe 26.6.2 for Mac systems. Updates can be applied via Settings > General > Software Update (iOS/iPadOS) or System Settings > General > Software Update (macOS). As an interim measure, avoid opening images from untrusted or unknown sources, and implement network controls to restrict image content from unverified origins (Apple iOS Advisory, Apple macOS Advisory).
The vulnerability was part of a broader Apple security release on August 17, 2026, which patched 122 flaws across iOS, iPadOS, and macOS. Coverage appeared on security news outlets and aggregators including SANS ISC and CyberKendra shortly after disclosure. No notable individual researcher commentary or significant social media debate specific to CVE-2026-65346 has been observed beyond standard patch reporting (SANS ISC, CyberKendra).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."