CVE-2026-65346Disclosure(apple / ipados)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • Peaked 5d ago at 3 mentions (2026-08-18); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline12 mentions / 7d
01223Mentions · 2026-08-17: 1Mentions · 2026-08-18: 3Mentions · 2026-08-19: 2Mentions · 2026-08-20: 3Mentions · 2026-08-22: 1Mentions · 2026-08-28: 1Mentions · 2026-08-31: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-08-18: 3Patch / Workaround · 2026-08-20: 3Patch / Workaround · 2026-08-31: 1Technical Details · 2026-08-18: 3Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 3Technical Details · 2026-08-22: 1Technical Details · 2026-08-31: 108-1708-1808-1908-2008-2208-2808-31
Signal classification4 categories
Disclosure
541.7%
Patch
541.7%
Active Exploitation
18.3%
General
18.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-171
Disclosure1
2026-08-183
Disclosure1Patch2
2026-08-192
Disclosure2
2026-08-203
Active Exploitation1Patch2
2026-08-221
Disclosure1
2026-08-281
General1
2026-08-311
Patch1
Full discourse12 posts
  • HalesFall 🪽@HalesFall
    Active Exploitation

    Come post your brilliant ideas in the comments, you arrogant plonkers. Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346) You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES. Your "security" is contingent upon the GOODWILL of other men. That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud. Skill Issue. The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really. It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes. @tayvano_ "DARKSWORD" And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE. I'll repost some others (non-exhaustive) since you people glossed over them: KISMET - NSO Group FORCEDENTRY - NSO Group FINDMYPWN - NSO Group PWNYOURHOME - NSO Group ENDOFDAYS - QuaDream BLASTPASS - NSO Group OPERATION TRIANGULATION - Unknown GRAPHITE - Paragon Solutions What else is there to say? ∙ North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z. They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river. It's a Graveyard of Rekt™ What battle? What defence? It's a slaughter and butcher. When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it. Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency. KEK North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry. And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far. Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming. You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet. Millions of lines of code on a multimedia entertainment device vs A compact codebase on dedicated hardware that has one job Not even Apple engineers would agree with you. DONKEY. ∙ @vidya_no68665 thinks he's clever with: >"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious." You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE. On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone. Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance). @__noided Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface. @n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it. Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off". If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified? ∙ History Lesson: Exploit after exploit, Apple was brought to their knees. In desperation, you know what Apple did in response? They sued the NSO Group. lol lmao even "PLS STOP HACKING US, PLSSSS" And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them. NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS. "In the wild" simply means "the good guys finally noticed bro". Great plan, everyone. Good work. Guess who discovers tons of iOS zero-days? Google Citizen Lab Amnesty Kaspersky Numerous independent researchers Anonymous reports Often, it's not even Apple themselves. Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple. Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing. @SatoshiSideho -- Apple has been getting Rekt™ for years @bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know? ∙ The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them. I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news". Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE. I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias. Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.

    Post summary

    The post reports that CVE‑2026‑65346 and CVE‑2026‑20700 were actively exploited in the wild, that Apple patched the vulnerabilities, and lists various exploit tool names, though it does not provide concrete PoC code or detailed exploitation steps.

    6021185.3K
    403 followersView on X
  • m4rio@m4rio_eth
    Patch

    !! Apple dropped a new security update. Top 3 fixes I’d prioritize: CVE-2026-64747 - kernel-level code execution CVE-2026-43723 - possible root privilege escalation CVE-2026-65346 code execution via malicious image processing If you manage Apple devices, patch these first. Kernel/root impact + easy-to-reach attack surface = highest priority. Please update!

    Post summary

    Apple released a patch addressing three kernel and privilege escalation CVEs; administrators should apply it promptly.

    1101311.2K
    4.2K followersView on X
  • hulaboy@0xhulaboy
    Patch

    Apple ออกอัปเดตความปลอดภัยสำหรับ iOS, iPadOS และ macOS เพื่อแก้ไขช่องโหว่ CVE-2026-65346 ซึ่งเป็นช่องโหว่ประเภท Integer Overflow ในระบบ ImageIO ช่องโหว่นี้อาจเปิดโอกาสให้ผู้ไม่หวังดีสามารถรันโค้ดอันตรายบนอุปกรณ์ได้ เพียงแค่ผู้ใช้งานเปิดดูรูปภาพที่ถูกแฝงโค้ดมาโดยเฉพาะ โดยช่องโหว่ดังกล่าวถูกค้นพบโดยทีม Red Team ของ Meta ซึ่งกระทบอุปกรณ์ iPhone, iPad และ Mac รุ่นล่าสุด

    Post summary

    Apple issued a security update for iOS, iPadOS, and macOS to fix CVE-2026-65346, an Integer Overflow in ImageIO that could allow remote code execution via a crafted image. The vulnerability was discovered by Meta's Red Team.

    00020165
    2.1K followersView on X
  • Rhett Bierman@rhettbierman7
    Patch

    What it actually patches Apple documented 29 CVEs. The important ones: • ImageIO — processing a crafted image could lead to arbitrary code execution (integer overflow, CVE-2026-65346) or a crash. This is the standout fix. • Kernel — three issues: a remote attacker could unexpectedly terminate the system; an app could crash the device or read/corrupt kernel memory. • Audio — an app could leak sensitive user information. • Telephony — an attacker in a privileged network position could bypass IPSec authentication and intercept traffic. • WebKit / Safari — the bulk of the list (about 21 items): malicious web pages that could crash Safari, corrupt memory, or (in one case) leak data via browsing history. • IOGPUFamily — malicious web content could cause memory corruption. ~Grok

    Post summary

    The entry details Apple's patching of 29 CVEs, providing targeted fixes for various components and summarizing the specific vulnerability types and impact areas.

    00010188
    1.4K followersView on X
  • Tech Start XYZ@TechStartXYZ
    Disclosure

    O destaque crítico é a CVE-2026-65346 no ImageIO (o framework nativo que processa imagens no sistema). Ela ocorre por um estouro de inteiros (integer overflow). Quando o sistema tenta gerar a miniatura de uma foto corrompida (no app Fotos ou no iMessage), o código malicioso estoura a memória e executa comandos remotos (RCE). Esse é o tipo de brecha mais cobiçado por spywares comerciais (como o Pegasus).

    Post summary

    The post reveals CVE-2026-65346 as a critical integer‑overflow flaw in Apple’s ImageIO that enables RCE during thumbnail generation for Photos and iMessage.

    1000049
    168 followersView on X
  • えり|缶ビール片手のAI / ガジェットウォッチャー@eri_ai_lav
    Disclosure

    ②WebKit以外の残り8件で怖いのはこの2つ ・ImageIO(CVE-2026-65346) 画像処理フレームワーク。画像を処理するだけで任意のコードが実行される恐れ。届いた1枚の画像が入口になる。 ・Telephony(CVE-2026-65329) IPSec認証を回避され、ネットワーク通信を傍受される可能性。対象はiPhone 11以降。

    Post summary

    The tweet lists two CVEs—ImageIO CVE‑2026‑65346 and Telephony CVE‑2026‑65329—emphasizing potential arbitrary code execution and IPSec authentication bypass on iPhone 11+ devices, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    10000201
    44 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    Apple iOS・iPadOS・macOSのImageIOに任意コード実行脆弱性 https://www.cybernote.click/2026/08/23/apple-ios-ipados-macos-cve-2026-65346-imageio-rce/ #IT #Security #cybersecurity

    Post summary

    The post announces the existence of a CVE (2026‑65346) affecting ImageIO on Apple platforms, but provides no further technical or operational details.

    0000074
    203 followersView on X
  • General Intels Daily@intels_daily
    Disclosure

    🟠 𝗛𝗜𝗚𝗛 · 𝗭𝗲𝗿𝗼 𝗱𝗮𝘆 🏢 Target: 𝗔𝗽𝗽𝗹𝗲, 𝗠𝗲𝘁𝗮 A vulnerability (CVE-2026-65346) in Apple's ImageIO framework allows for arbitrary code execution on iOS and macOS devices through image processing. Although no confirmed exploitation has been reported, the vulnerability's nature and past incidents raise concerns about potential zero-click attacks. #ZeroDay #0day #ThreatIntel #CTI

    Post summary

    A new zero-day CVE-2026-65346 affecting Apple's ImageIO framework was disclosed, permitting arbitrary code execution through image processing, but no exploitation has yet been reported.

    00000209
    157 followersView on X
  • 「色即是空」な「空即是色」blog@shikisokukusoku
    Patch

    Appleが緊急更新を公開。画像処理の仕組み「ImageIO」に脆弱性(CVE-2026-65346)。悪意ある画像を開くだけで乗っ取られる恐れがあり、早めの更新を推奨。 #Apple #セキュリティ https://support.apple.com/en-us/148282

    Post summary

    Apple released an emergency update for CVE-2026-65346 in ImageIO, mitigating the risk of remote takeover via malicious images; no PoC, exploit code, or active exploitation evidence is referenced.

    0000095
    350 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-65346 An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lea… https://www.cve.org/CVERecord?id=CVE-2026-65346 ----- Traducción: CVE-2026-65346 Se … https://infoflow.cloud`

    Post summary

    The post announces the CVE-2026-65346 integer‑overflow vulnerability, notes it’s fixed in recent OS releases, and provides minimal technical detail without indicating exploitation or PoC.

    00000124
    100 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-65346 An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lea… https://www.cve.org/CVERecord?id=CVE-2026-65346

    Post summary

    CVE-2026-65346, an integer overflow bug, is fixed in iOS 26.6.1, iPadOS 26.6.1, and macOS 26.6.2 via improved input validation; no exploitation or PoC details are disclosed.

    00000728
    58.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Apple iOS and other products (CVE-2026-65346) https://vuldb.com/vuln/391488

    Post summary

    A severe Apple iOS vulnerability (CVE‑2026‑65346) has been disclosed, but the post lacks specific technical details, PoC references, or patch information.

    00000127
    2.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more