Apple ImageIO Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

Vulnerability

A vulnerability in the ImageIO framework of Apple products, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, allows for a denial-of-service condition. This issue arises from an out-of-bounds write, which can be exploited by processing maliciously crafted files or images, leading to unexpected application termination.

Impact

Exploitation of this vulnerability causes a denial-of-service condition by terminating the affected application.

Remediation

Users can update to the latest versions of iOS, iPadOS, macOS Sequoia, macOS Sonoma, tvOS, visionOS, or watchOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.

Added: May 11, 2026, 9:42 PM
Updated: May 11, 2026, 9:42 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.2
remediation
7.7
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.