A newly patched Apple security flaw could let attackers execute malicious code when an iPhone or iPad processes an image.
Apple released iOS and iPadOS 26.6.1 on Aug. 17 to address the issue alongside other security vulnerabilities. Two days later, India’s Computer Emergency Response Team, CERT-In, issued a critical advisory warning that vulnerabilities across Apple products could enable arbitrary code execution, expose sensitive information, compromise security boundaries, or crash affected devices.
The warning gives iPhone and iPad users a clear reason to update quickly. CERT-In rates the overall risk as “Very High,” although neither Apple nor CERT-In has identified active exploitation of the vulnerabilities patched in iOS and iPadOS 26.6.1.
Apple image flaw could allow malicious code execution
One of the most serious vulnerabilities fixed in iOS and iPadOS 26.6.1 affects ImageIO, an Apple framework for processing image data.
Apple said that processing an image could lead to arbitrary code execution due to an integer overflow vulnerability. The company addressed the problem with improved input validation.
The flaw is identified as CVE-2026-65346.
Apple does not specify what type of image or attack sequence would be required to successfully exploit the vulnerability. Its security advisory also does not describe CVE-2026-65346 as a zero-click vulnerability or say that attackers are actively exploiting it.
Still, arbitrary code execution is among the more serious potential outcomes of a software vulnerability because it can allow an attacker to make a targeted device run unauthorized instructions.
Across the Apple products covered by CERT-In’s security advisory, vulnerabilities affect components including CoreAudio, ImageIO, the kernel, WebKit, IOGPUFamily, AVEVideoEncoder, SceneKit, Model I/O, and other system frameworks.
CERT-In said the underlying weaknesses include memory corruption, use-after-free bugs, out-of-bounds reads and writes, buffer and integer overflows, type confusion, and authentication, authorization, permission, and logic issues.
Successful exploitation could enable arbitrary code execution with elevated privileges, access to sensitive information, security boundary compromises, or denial-of-service conditions, according to CERT-In.
Apple has dealt with similarly serious threats before. In February, the company patched an actively exploited Apple zero-day that enabled arbitrary code execution after saying the vulnerability had been used in “extremely sophisticated” attacks against specific individuals.
WebKit, Apple’s browser engine, has also repeatedly attracted attacker attention. Two WebKit zero-days patched in late 2025 were used in targeted iPhone spyware attacks, highlighting the potential risks posed by vulnerabilities in components that routinely process web content.
Which Apple devices are affected?
Apple says iOS and iPadOS 26.6.1 is available for:
- iPhone 11 and later
- iPad Pro 12.9-inch, 3rd generation and later
- iPad Pro 11-inch, 1st generation and later
- iPad Air, 3rd generation and later
- iPad, 8th generation and later
- iPad mini, 5th generation and later
CERT-In’s broader advisory identifies devices running versions earlier than the following as affected:
- iOS 26.6.1
- iPadOS 26.6.1
- iOS 18.7.10
- iPadOS 18.7.10
- macOS Tahoe 26.6.2
Users running affected software should install the appropriate security update provided by Apple.
On an iPhone or iPad, users can check for an available update by going to:
Settings > General > Software Update
Apple provides a full breakdown of the fixes in its iOS and iPadOS 26.6.1 security advisory.
Apple’s update fixes more than the ImageIO flaw
The ImageIO vulnerability is one of numerous security issues addressed by iOS and iPadOS 26.6.1.
Apple’s security bulletin documents vulnerabilities affecting components including Audio, ImageIO, IOGPUFamily, the kernel, Telephony, and WebKit, among other parts of the operating system.
Among them, Apple says one kernel vulnerability could allow an app to cause an unexpected system termination or read kernel memory. A separate kernel vulnerability could allow a remote attacker to cause an unexpected system termination.
The update also fixes WebKit vulnerabilities that could cause an unexpected Safari crash or memory corruption when a device processes maliciously crafted web content.
The latest fixes follow Apple’s July 27 release of iOS and iPadOS 26.6, which addressed another large batch of security vulnerabilities. Apple’s security notes for iOS 26.6 and iPadOS 26.6 detail vulnerabilities that could lead to kernel-level code execution, unauthorized data access, and other security issues.
The steady stream of fixes underscores why keeping iPhones and iPads updated matters even when a device appears to be functioning normally.
iPhones remain targets for sophisticated attacks
The latest vulnerabilities come amid continued interest among sophisticated threat actors in iPhones.
Earlier this year, Google researchers uncovered Coruna, an iOS exploit framework containing 23 vulnerabilities spread across five exploit chains. The toolkit was reportedly used to compromise thousands of iPhones.
The Coruna campaign is separate from the vulnerabilities addressed in iOS and iPadOS 26.6.1, and there is no evidence connecting the two.
CERT-In also issued a separate Apple advisory on Aug. 14 concerning threat notifications sent to users targeted by mercenary spyware operators. The agency described those attacks as sophisticated operations typically associated with state-sponsored or highly resourced adversaries.
That warning is separate from the vulnerabilities covered in CERT-In’s Aug. 19 advisory.
Are attackers exploiting these Apple flaws?
Neither Apple’s security bulletin nor CERT-In’s Aug. 19 advisory says the vulnerabilities patched in iOS and iPadOS 26.6.1 are being actively exploited.
A vulnerability capable of arbitrary code execution can still pose a serious security risk without evidence of active exploitation. CERT-In rates the advisory Critical and warns of the potential for sophisticated targeted attacks.
The agency recommends applying the appropriate Apple security updates rather than waiting for evidence of attacks.
What iPhone and iPad users should do now
Apple users should check whether the latest security update is available for their devices by navigating to:
Settings > General > Software Update
Users with compatible devices should install iOS or iPadOS 26.6.1 or the latest supported security update available for their device.
Enabling automatic updates can also help reduce the amount of time a device remains exposed after Apple releases future security fixes.
Organizations managing fleets of iPhones, iPads, or Macs should verify the deployed operating system versions through their device management tools and prioritize patching systems for users at elevated targeting risk.
Apple’s latest update is a reminder that even routine-looking iPhone updates can contain important security fixes. With an ImageIO vulnerability that could allow arbitrary code execution among the issues patched this week, users have good reason not to leave this one sitting in the update queue.
Also read: As cyber threats evolve alongside AI, see why OpenAI is slowing frontier AI training as Astra nears a critical cybersecurity threshold.





