Vulnerability
Published 2026-09-14
Verified 2026-09-27

Apple ImageIO CVE-2026-86869: EXR out-of-bounds write — ironPeak EX-ARRR details 0-click iMessage path (patched 14 Sep)

Apple security content for iOS/iPadOS 26.7 (support 149041, released 14 September 2026) and macOS Golden Gate 27 (149035) lists CVE-2026-86869 in ImageIO: out-of-bounds write addressed with improved bounds checking; Apple impact text on 26.7 is “Processing a maliciously crafted image may lead to unexpected app termination” (credits: Niels Hofmans, Meta Red Team X, Geonha Lee, Chris Bailey — Short Circuit). UPDATE 26 Sep 2026: ironPeak blog EX-ARRR publishes full technical disclosure — heap overflow in libAppleEXR.dylib / CompressedInterleave4 when decoding crafted OpenEXR; researcher states Apple triage classified the report as 0-click code execution via iMessage EXR image payload, with BlastDoor not decoding EXR and Spotlight/ImageIO thumbnailing providing the side-door reach; PAC/MIE still constrain reliable exploitation on modern Apple silicon. Reported May 2026; fixed across iOS/iPadOS/macOS 27 family builds as CVE-2026-86869 per researcher timeline. No CVSS from Apple. Patch: current iOS/iPadOS 26.7+ / macOS 27 (Golden Gate) / equivalent trains. Distinct from bulk desk card apple-ios27-20260914 (does not spotlight this CVE). Primary: Apple iOS 26.7 security content; technical write-up: ironPeak.

Product
Apple ImageIO / libAppleEXR (iOS, iPadOS, macOS)
Versions
Fixed in iOS/iPadOS 26.7 (149041) and macOS Golden Gate 27 (149035) per Apple listings; researcher: fixed across iOS/iPadOS/macOS 27 family. Older trains remain exposed until updated.
Exploited in Australia?
unknown
Patch to
Update to iOS/iPadOS 26.7 or later and macOS Golden Gate 27 / current security update for your train; prioritise internet-facing iMessage/Mail image-decode paths; do not rely on BlastDoor alone for exotic image formats

Primary: Apple — iOS 26.7 and iPadOS 26.7 security content (CVE-2026-86869 ImageIO, 14 Sep 2026) · Vendor: Apple — iOS/iPadOS 26.7 ImageIO CVE-2026-86869 · CVE: CVE-2026-86869 · ironPeak — EX-ARRR: OpenEXR / libAppleEXR 0-click iMessage path (26 Sep 2026)

vulnerabilities