Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector.
The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files.
Discovered and reported by Nik Tsytsarkin of Meta's Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image.
The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models.
Apple said it addressed the flaw with improved input validation, and experts urged users to install the August 17 updates as soon as possible.
Adam Boynton, senior enterprise strategy manager at Jamf, said: "iOS 26.6.1's standout fix is CVE-2026-65346, an integer overflow in ImageIO. This is Apple's system framework for decoding images and exploiting it could allow an attacker to write memory where they shouldn't and gain code execution.
"Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals."
Several of the most damaging spyware campaigns in recent years have used zero-click smartphone exploits triggered by malicious files delivered through messaging services.
Operation Triangulation, which Russia's FSB claimed was the work of the NSA, used such tactics. So did FORCEDENTRY, an exploit used to deliver NSO Group's Pegasus spyware through Apple's image-processing software.
The Register asked Apple if it was aware of CVE-2026-65346 being used in spyware campaigns, but it did not immediately respond.
Most of the other vulnerabilities in the iOS 26.6.1 update are, surprise, surprise, in WebKit – arguably Apple's most pummeled framework.
Boynton also highlighted CVE-2026-65329 as one of the batch's more concerning flaws.
Affecting iPhone 11 and later, the vulnerability lies in Apple's Telephony component and could allow an attacker to intercept network traffic.
Apple said an attacker would need a privileged network position to exploit the bug, bypass IPsec authentication, and intercept traffic.