Apple Rushes Fix For A Photo Bug That Could Hijack Your iPhone
A single malicious image could have been enough to hijack an iPhone or Mac. Apple's emergency patch closes a zero-click flaw found by Meta's own security team.

Image credit: AI-generated image
Apple has pushed out emergency security updates to close a flaw serious enough that simply receiving the wrong image could have been enough to compromise an iPhone, iPad or Mac. The bug, tracked as CVE-2026-65346, sat inside ImageIO, the core Apple framework nearly every app relies on to open and render pictures.
What Went Wrong Inside ImageIO
The vulnerability is an integer-overflow bug, a type of flaw where a program miscalculates a number in a way that lets an attacker write data into parts of memory it was never meant to touch. In this case, that mistake could be triggered by a specially crafted image, opening the door to arbitrary code execution on the affected device. The bug was found and reported by Nik Tsytsarkin of Meta's Red Team X, the internal security unit Meta uses to hunt for exactly this kind of high-impact flaw before criminals do.
Which Devices Need The Update
The flaw affects Macs running macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, standard iPad and iPad mini models. Apple's fix, released on August 17, 2026, arrived as macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, and separate updates for older devices, iOS 18.7.10 and iPadOS 18.7.10. The company addressed the underlying issue with improved input validation, essentially teaching ImageIO to reject the malformed data that made the exploit possible in the first place.
Why Zero-Click Bugs Are The Scary Kind
What makes this category of bug particularly dangerous is the word zero-click. Most security threats need a user to do something first, tap a link, download a file, approve a prompt. A flaw inside image processing can potentially be triggered just by a device receiving and rendering a picture, with no interaction required at all. That is the same class of vulnerability that has historically been prized by spyware operators, since it removes the human error that most attacks still depend on. Apple has not said publicly whether this specific bug was ever exploited in the wild, but the potential for silent, no-tap compromise is exactly why security researchers treat these patches as urgent rather than routine.
What You Should Do Right Now
The fix is already available, which means the only real action needed is updating. On an iPhone or iPad, that means checking Settings, General, Software Update, and installing the latest version for your device. Mac users should do the same through System Settings. This patch arrived alongside a broader bundle of fixes addressing roughly two dozen other security issues across Apple's operating systems, making this a good moment to update every Apple device in the house rather than just the one you use most.
Source links
Comments
No approved comments yet.


