
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20634 is a memory disclosure vulnerability in Apple's ImageIO framework caused by improper memory handling when processing maliciously crafted SGI image files. Discovered and reported by George Karchemsky (@gkarchemsky) working with Trend Micro Zero Day Initiative, it was publicly disclosed on February 11, 2026. Affected platforms include iOS/iPadOS (before 18.7.5 and before 26.3), macOS Sonoma (before 14.8.4), macOS Sequoia (before 15.7.4), macOS Tahoe (before 26.3), tvOS (before 26.3), watchOS (before 26.3), and visionOS (before 26.3). It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory, Feedly).
The root cause is a buffer over-read in the Apple ImageIO framework (CWE-125), where crafted data embedded in SGI image files can trigger a read past the end of an allocated buffer, resulting in disclosure of process memory contents. The attack vector is local (AV:L) and requires user interaction — specifically, a user must open or process a maliciously crafted image file — but requires no privileges. The Zero Day Initiative advisory (ZDI-26-175) provides additional technical context, confirming the flaw resides in SGI image parsing within ImageIO (Apple Advisory, ZDI Advisory).
Successful exploitation results in disclosure of process memory contents to an attacker, posing a high confidentiality risk with no integrity or availability impact. The leaked memory could contain sensitive data such as cryptographic material, credentials, or other in-memory secrets belonging to the process handling the image. When chained with other vulnerabilities, this information disclosure could facilitate further exploitation such as bypassing ASLR to enable arbitrary code execution (Apple Advisory, Feedly).
.sgi, .rgb, .rgba, .bw) in temporary directories, downloads folders, or mail/message attachment caches.ImageIO framework crashes or memory access violations when processing image files; look for ReportCrash entries involving image-handling processes.Apple has released patches across all affected platforms: iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3. Users and administrators should apply these updates immediately via System Settings > Software Update (macOS) or Settings > General > Software Update (iOS/iPadOS). As a temporary workaround prior to patching, avoid opening SGI image files from untrusted sources, and consider blocking SGI image file types at network or email gateway boundaries (Apple Advisory, Apple Advisory, Apple Advisory).
The vulnerability was reported through the Trend Micro Zero Day Initiative by researcher George Karchemsky (@gkarchemsky), who also discovered the related CVE-2026-20675 in the same ImageIO component. The ZDI published advisory ZDI-26-175 on March 10, 2026, providing additional technical details. Coverage appeared in security news outlets and aggregators including SANS ISC and BeyondMachines in the context of Apple's broader February 2026 security update cycle, which addressed over 90 vulnerabilities across Apple platforms (ZDI Advisory, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."