{"id":43498,"date":"2026-08-18T21:19:56","date_gmt":"2026-08-18T21:19:56","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=43498"},"modified":"2026-08-18T21:19:56","modified_gmt":"2026-08-18T21:19:56","slug":"apple-plugs-image-processing-hole-ripe-for-spyware-abuse","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=43498","title":{"rendered":"Apple plugs image-processing hole ripe for spyware abuse"},"content":{"rendered":"<p>Patch batch spans current kit, older iGadgets, Macs, and Vision Pro<\/p>\n<p>Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector.<\/p>\n<p>The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to parse image files.<\/p>\n<p>Discovered and reported by Nik Tsytsarkin of Meta&#039;s Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image.<\/p>\n<p>The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models.<\/p>\n<p>Apple said it addressed the flaw with improved input validation, and experts urged users to install the August 17 updates as soon as possible.<\/p>\n<p>Adam Boynton, senior enterprise strategy manager at Jamf, said: &quot;iOS 26.6.1&#039;s standout fix is CVE-2026-65346, an integer overflow in ImageIO. This is Apple&#039;s system framework for decoding images and exploiting it could allow an attacker to write memory where they shouldn&#039;t and gain code execution.\u00a0<\/p>\n<p>&quot;Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals.&quot;<\/p>\n<p>Several of the most damaging spyware campaigns in recent years have used zero-click smartphone exploits triggered by malicious files delivered through messaging services.<\/p>\n<p>Operation Triangulation, which Russia&#039;s FSB claimed was the work of the NSA, used such tactics. So did FORCEDENTRY, an exploit used to deliver NSO Group&#039;s Pegasus spyware through Apple&#039;s image-processing software.<\/p>\n<p>The Register asked Apple if it was aware of CVE-2026-65346 being used in spyware campaigns, but it did not immediately respond.\u00a0<\/p>\n<p>Most of the other vulnerabilities in the iOS 26.6.1 update are, surprise, surprise, in WebKit \u2013 arguably Apple&#039;s most pummeled framework.<\/p>\n<p>Boynton also highlighted CVE-2026-65329 as one of the batch&#039;s more concerning flaws.<\/p>\n<p>Affecting iPhone 11 and later, the vulnerability lies in Apple&#039;s Telephony component and could allow an attacker to intercept network traffic.<\/p>\n<p>Apple said an attacker would need a privileged network position to exploit the bug, bypass IPsec authentication, and intercept traffic.<\/p>\n<p><em>Source: <a href='https:\/\/www.theregister.com\/security\/2026\/08\/18\/apple-plugs-image-processing-hole-ripe-for-spyware-abuse\/5289031' target='_blank'>Read the original article on www.theregister.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Patch batch spans current kit, older iGadgets, Macs, and Vision Pro Apple has released a batch of vulnerability fixes for iPhones, iPads, and Macs, including an image-processing flaw that experts say has the hallmarks of a spyware delivery vector. The most notable patch is for CVE-2026-65346, a defect in the ImageIO framework Apple uses to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,3],"tags":[13,28,34],"class_list":["post-43498","post","type-post","status-publish","format-standard","hentry","category-share-suggestions","category-technology","tag-impact-aapl","tag-signal-buy","tag-stage-stage-2"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/43498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=43498"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/43498\/revisions"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=43498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=43498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=43498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}