Apple patches ImageIO code-execution flaw CVE-2026-65346 in iPhone, iPad, Mac, and Vision Pro updates

Apple released security updates for iPhones, iPads, Macs, and Vision Pro that fix an image-processing bug that could let a malicious file take control of a device. The key issue, CVE-2026-65346, is an integer-overflow flaw in the ImageIO framework that parses image files and can lead to arbitrary code execution. Apple shipped fixes in iOS 26.6.1, related macOS Tahoe updates, and updates for supported iPad models and older devices on iOS 18.7.10/iPadOS 18.7.10; the batch also includes CVE-2026-65329 in Telephony, which could allow traffic interception from a privileged network position.
Why it matters: Image-parsing bugs have repeatedly been used in zero-click spyware attacks, so this is the kind of flaw high-risk users and enterprise defenders should treat seriously. Apple users and device administrators should install the latest updates promptly, including on older supported iPhones and iPads.

Sources

Apple plugs image-processing hole ripe for spyware abuse
2026.08.18 100% relevant
This article establishes a distinct Apple security-update story centered on CVE-2026-65346 and its spyware-relevant image-processing risk; no existing tracked story covers this specific August 2026 Apple patch batch or this CVE.
← Back to all stories