
Shout out to my Meta Red Team X colleagues for the fun of finding an EXR ImageIO bug in iOS 26.7 (CVE-2026-86869) - love it when you see a gallery crash on a Friday afternoon and hammer out a report together ❤️ Thanks @bellis1000 for the initial EXR write-up of CVE-2026-28990 - it directed us (and others it seems) to research the surface! tl;dr: bug was a linear oob write when rendering an EXR with a 4th alpha channel on an allocation meant for 3 channels.



