ELSEIF
Your brief EB
361 stories from 110 feeds 398 clusters Refreshed 7 minutes ago next pull 17:07

TECH Signal 439

Apple patches ImageIO integer overflow that could allow spyware code execution on iPhones, iPads, Macs, and Vision Pro

Apple's August 17 security updates batch fixes an ImageIO integer overflow that could allow arbitrary code execution via image processing, plus a Telephony flaw that could bypass IPsec, across current and older devices.

WHY IT MATTERS

Image parsing is a known vector for zero-click spyware, so this patch is urgent for anyone handling sensitive communications. The Telephony flaw also requires a privileged network position to intercept traffic, which matters for organizations relying on IPsec. Install the updates promptly, especially on devices that may be targeted.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

CVE-2026-65346 is an integer overflow in ImageIO that could allow arbitrary code execution when processing images.

02

CVE-2026-65329 in Telephony could let an attacker with a privileged network position bypass IPsec authentication and intercept traffic.

03

The patch batch covers iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe, visionOS 26.6.1, and older devices via iOS 18.7.10.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Apple plugs image-processing hole ripe for spyware abuse Open ↗