CVE-2026-20634
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20634 is a memory disclosure vulnerability in Apple's ImageIO framework caused by improper memory handling when processing maliciously crafted SGI image files. Discovered and reported by George Karchemsky (@gkarchemsky) working with Trend Micro Zero Day Initiative, it was publicly disclosed on February 11, 2026. Affected platforms include iOS/iPadOS (before 18.7.5 and before 26.3), macOS Sonoma (before 14.8.4), macOS Sequoia (before 15.7.4), macOS Tahoe (before 26.3), tvOS (before 26.3), watchOS (before 26.3), and visionOS (before 26.3). It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory, Feedly).

Technical details

The root cause is a buffer over-read in the Apple ImageIO framework (CWE-125), where crafted data embedded in SGI image files can trigger a read past the end of an allocated buffer, resulting in disclosure of process memory contents. The attack vector is local (AV:L) and requires user interaction — specifically, a user must open or process a maliciously crafted image file — but requires no privileges. The Zero Day Initiative advisory (ZDI-26-175) provides additional technical context, confirming the flaw resides in SGI image parsing within ImageIO (Apple Advisory, ZDI Advisory).

Impact

Successful exploitation results in disclosure of process memory contents to an attacker, posing a high confidentiality risk with no integrity or availability impact. The leaked memory could contain sensitive data such as cryptographic material, credentials, or other in-memory secrets belonging to the process handling the image. When chained with other vulnerabilities, this information disclosure could facilitate further exploitation such as bypassing ASLR to enable arbitrary code execution (Apple Advisory, Feedly).

Exploitation steps

  1. Craft a malicious SGI image: Create a specially crafted SGI image file with malformed data designed to trigger an out-of-bounds read in Apple's ImageIO framework when parsed.
  2. Deliver the payload: Distribute the malicious image via email attachment, messaging app, web page, or any other vector that causes the target device to process the image (e.g., embedding it in a webpage viewed in Safari, or sending it via iMessage).
  3. Trigger image processing: Induce the victim to open or preview the image, causing the ImageIO framework to parse the SGI file and read past the end of an allocated buffer.
  4. Capture disclosed memory: The out-of-bounds read leaks process memory contents, which may be captured by the attacker if the image is processed in a context where output is returned (e.g., a server-side image processing service) or used as an information leak primitive in a multi-stage exploit chain to defeat ASLR (ZDI Advisory, Apple Advisory).

Indicators of compromise

  • File System: Presence of unexpected or suspicious SGI image files (.sgi, .rgb, .rgba, .bw) in temporary directories, downloads folders, or mail/message attachment caches.
  • Logs: Crash reports or diagnostic logs referencing ImageIO framework crashes or memory access violations when processing image files; look for ReportCrash entries involving image-handling processes.
  • Process: Unusual child processes or memory dumps spawned by image-processing applications (e.g., Photos, Mail, Safari, Messages) shortly after opening an image file.
  • Network: Inbound delivery of SGI image files from untrusted or unexpected external sources via email, web, or messaging protocols.

Mitigation and workarounds

Apple has released patches across all affected platforms: iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3. Users and administrators should apply these updates immediately via System Settings > Software Update (macOS) or Settings > General > Software Update (iOS/iPadOS). As a temporary workaround prior to patching, avoid opening SGI image files from untrusted sources, and consider blocking SGI image file types at network or email gateway boundaries (Apple Advisory, Apple Advisory, Apple Advisory).

Community reactions

The vulnerability was reported through the Trend Micro Zero Day Initiative by researcher George Karchemsky (@gkarchemsky), who also discovered the related CVE-2026-20675 in the same ImageIO component. The ZDI published advisory ZDI-26-175 on March 10, 2026, providing additional technical details. Coverage appeared in security news outlets and aggregators including SANS ISC and BeyondMachines in the context of Apple's broader February 2026 security update cycle, which addressed over 90 vulnerabilities across Apple platforms (ZDI Advisory, SANS ISC).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management