The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.

cve CVE-2026-65347 1 source, 1 claim · Watch

NVD writes:
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service. the claim

What it is to other things

affectsapple/ipados
NVD
affectsapple/iphone_os
NVD
affectsapple/macos
NVD
made_byapple
NVD

In words only, so not counted until a person confirms one:

affectsapple/ios_and_ipados
NVD says “Apple · iOS and iPadOS”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service."
      }
    ],
    "id": "CVE-2026-65347",
    "lastModified": "2026-09-14T21:17:19.703",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65347",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:01:30.283180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.390",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149036"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDiOS and iPadOS
receipt
Source
NVD
Its words
iOS and iPadOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCiOS and iPadOS
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service."
      }
    ],
    "id": "CVE-2026-65347",
    "lastModified": "2026-09-14T21:17:19.703",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65347",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:01:30.283180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.390",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149036"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service."
      }
    ],
    "id": "CVE-2026-65347",
    "lastModified": "2026-09-14T21:17:19.703",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65347",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:01:30.283180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.390",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149036"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.1",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.6.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "tvOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "visionOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "watchOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "DFD48325-D4E4-40C9-B64B-DB5F12A3AF0F",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "2CC8252A-05E1-415B-81AF-0C99BEC864AA",
                "versionEndExcluding": "26.6.1",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "ECE169FD-8BEB-45FE-82CE-FC98AD8EB3CA",
                "versionEndExcluding": "26.6.2",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service."
      }
    ],
    "id": "CVE-2026-65347",
    "lastModified": "2026-09-14T21:17:19.703",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65347",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-18T13:01:30.283180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-17T22:17:25.390",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148281"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Release Notes",
          "Vendor Advisory"
        ],
        "url": "https://support.apple.com/en-us/148282"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149036"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149037"
      },
      {
        "source": "product-security@apple.com",
        "url": "https://support.apple.com/en-us/149038"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-400"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.
zetlyn/cve-nvd · 2026-08-17
cvss 6.5 product iOS and iPadOS status Modified vendor Apple source