Apple Patches Critical iPhone Flaws: Attackers Could Run Malicious Code

A newly patched Apple safety flaw might let attackers execute malicious code when an iPhone or iPad processes a picture.

Apple launched iOS and iPadOS 26.6.1 on Aug. 17 to deal with the difficulty alongside different safety vulnerabilities. Two days later, India’s Laptop Emergency Response Crew, CERT-In, issued a important advisory warning that vulnerabilities throughout Apple merchandise might allow arbitrary code execution, expose delicate data, compromise safety boundaries, or crash affected gadgets.

The warning provides iPhone and iPad customers a transparent motive to replace shortly. CERT-In charges the general threat as “Very Excessive,” though neither Apple nor CERT-In has recognized lively exploitation of the vulnerabilities patched in iOS and iPadOS 26.6.1.

Apple picture flaw might permit malicious code execution

Probably the most critical vulnerabilities fastened in iOS and iPadOS 26.6.1 impacts ImageIO, an Apple framework for processing picture information.

Apple mentioned that processing a picture might result in arbitrary code execution as a consequence of an integer overflow vulnerability. The corporate addressed the issue with improved enter validation.

The flaw is recognized as CVE-2026-65346.

Apple doesn’t specify what sort of picture or assault sequence can be required to efficiently exploit the vulnerability. Its safety advisory additionally doesn’t describe CVE-2026-65346 as a zero-click vulnerability or say that attackers are actively exploiting it.

Nonetheless, arbitrary code execution is among the many extra critical potential outcomes of a software program vulnerability as a result of it could possibly permit an attacker to make a focused machine run unauthorized directions.

Throughout the Apple merchandise lined by CERT-In’s security advisory, vulnerabilities have an effect on elements together with CoreAudio, ImageIO, the kernel, WebKit, IOGPUFamily, AVEVideoEncoder, SceneKit, Mannequin I/O, and different system frameworks.

CERT-In mentioned the underlying weaknesses embody reminiscence corruption, use-after-free bugs, out-of-bounds reads and writes, buffer and integer overflows, sort confusion, and authentication, authorization, permission, and logic points.

Profitable exploitation might allow arbitrary code execution with elevated privileges, entry to delicate data, safety boundary compromises, or denial-of-service situations, in response to CERT-In.

Apple has handled equally critical threats earlier than. In February, the corporate patched an actively exploited Apple zero-day that enabled arbitrary code execution after saying the vulnerability had been utilized in “extraordinarily subtle” assaults in opposition to particular people.

WebKit, Apple’s browser engine, has additionally repeatedly attracted attacker consideration. Two WebKit zero-days patched in late 2025 have been used in targeted iPhone spyware attacks, highlighting the potential dangers posed by vulnerabilities in elements that routinely course of internet content material.

Which Apple gadgets are affected?

Apple says iOS and iPadOS 26.6.1 is accessible for:

  • iPhone 11 and later
  • iPad Professional 12.9-inch, third technology and later
  • iPad Professional 11-inch, 1st technology and later
  • iPad Air, third technology and later
  • iPad, eighth technology and later
  • iPad mini, fifth technology and later

CERT-In’s broader advisory identifies gadgets working variations sooner than the next as affected:

  • iOS 26.6.1
  • iPadOS 26.6.1
  • iOS 18.7.10
  • iPadOS 18.7.10
  • macOS Tahoe 26.6.2

Customers working affected software program ought to set up the suitable safety replace offered by Apple.

On an iPhone or iPad, customers can examine for an obtainable replace by going to:

Settings > Normal > Software program Replace

Apple offers a full breakdown of the fixes in its iOS and iPadOS 26.6.1 security advisory.

Apple’s replace fixes greater than the ImageIO flaw

The ImageIO vulnerability is one in every of quite a few safety points addressed by iOS and iPadOS 26.6.1.

Apple’s safety bulletin paperwork vulnerabilities affecting elements together with Audio, ImageIO, IOGPUFamily, the kernel, Telephony, and WebKit, amongst different elements of the working system.

Amongst them, Apple says one kernel vulnerability might permit an app to trigger an sudden system termination or learn kernel reminiscence. A separate kernel vulnerability might permit a distant attacker to trigger an sudden system termination.

The replace additionally fixes WebKit vulnerabilities that might trigger an sudden Safari crash or reminiscence corruption when a tool processes maliciously crafted internet content material.

The most recent fixes observe Apple’s July 27 launch of iOS and iPadOS 26.6, which addressed one other massive batch of safety vulnerabilities. Apple’s security notes for iOS 26.6 and iPadOS 26.6 element vulnerabilities that might result in kernel-level code execution, unauthorized information entry, and different safety points.

The regular stream of fixes underscores why protecting iPhones and iPads up to date issues even when a tool seems to be functioning usually.

iPhones stay targets for classy assaults

The most recent vulnerabilities come amid continued curiosity amongst subtle risk actors in iPhones.

Earlier this 12 months, Google researchers uncovered Coruna, an iOS exploit framework containing 23 vulnerabilities unfold throughout 5 exploit chains. The toolkit was reportedly used to compromise thousands of iPhones.

The Coruna marketing campaign is separate from the vulnerabilities addressed in iOS and iPadOS 26.6.1, and there’s no proof connecting the 2.

CERT-In additionally issued a separate Apple advisory on Aug. 14 regarding risk notifications despatched to customers focused by mercenary spyware and adware operators. The company described these assaults as subtle operations sometimes related to state-sponsored or extremely resourced adversaries.

That warning is separate from the vulnerabilities lined in CERT-In’s Aug. 19 advisory.

Are attackers exploiting these Apple flaws?

Neither Apple’s safety bulletin nor CERT-In’s Aug. 19 advisory says the vulnerabilities patched in iOS and iPadOS 26.6.1 are being actively exploited.

A vulnerability able to arbitrary code execution can nonetheless pose a critical safety threat with out proof of lively exploitation. CERT-In charges the advisory Crucial and warns of the potential for classy focused assaults.

The company recommends making use of the suitable Apple safety updates slightly than ready for proof of assaults.

What iPhone and iPad customers ought to do now

Apple customers ought to examine whether or not the most recent safety replace is accessible for his or her gadgets by navigating to:

Settings > Normal > Software program Replace

Customers with appropriate gadgets ought to set up iOS or iPadOS 26.6.1 or the most recent supported safety replace obtainable for his or her machine.

Enabling automated updates also can assist cut back the period of time a tool stays uncovered after Apple releases future safety fixes.

Organizations managing fleets of iPhones, iPads, or Macs ought to confirm the deployed working system variations by their machine administration instruments and prioritize patching methods for customers at elevated concentrating on threat.

Apple’s newest replace is a reminder that even routine-looking iPhone updates can comprise essential safety fixes. With an ImageIO vulnerability that might permit arbitrary code execution among the many points patched this week, customers have good motive to not depart this one sitting within the replace queue.

Additionally learn: As cyber threats evolve alongside AI, see why OpenAI is slowing frontier AI training as Astra nears a critical cybersecurity threshold.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *