|

Update Your iPhone and Mac Right Now. Apple Just Patched a Serious Spyware-Grade Flaw.

Apple released emergency security updates on August 17 — two days ago — and if you haven’t installed them yet, you should do it now. Not eventually. Now.

The updates include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. Apple said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases. In total, Apple patched 122 flaws across its platforms. Most of them are serious. One of them is the kind of vulnerability that has historically been used to install spyware on iPhones without the target doing anything at all.

The Flaw That Matters Most: CVE-2026-65346

The centrepiece of this update is a vulnerability tracked as CVE-2026-65346. It lives in ImageIO — the Apple framework that handles how your devices read and display image files.

Discovered and reported by Nik Tsytsarkin of Meta’s Red Team X, CVE-2026-65346 is an integer-overflow bug that could allow arbitrary code execution when an affected device processes an image. The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models.

In plain English: a specially crafted image file — a JPEG, a PNG, a HEIC, anything your device might receive or display — could trigger this flaw and give an attacker the ability to run code on your device. Your device. Without you clicking anything. Without you opening a file. Just receiving an image through iMessage, WhatsApp, or email could be enough.

These are the same sort of attacks used to plant spyware on an iPhone, via so-called zero-click attacks where a user only has to receive an image on WhatsApp or iMessage to become a victim.

What Zero-Click Actually Means

Most people understand conventional attacks: you click a bad link, you open a malicious attachment, you install something you shouldn’t. You did something.

Zero-click attacks are different. They require no action from the victim whatsoever. The malicious payload — in this case, a crafted image — arrives on your device. Your device processes it automatically, because that’s what devices do with images. The flaw triggers during that automatic processing. The attack succeeds before you’ve even seen the image.

This is the delivery mechanism used for some of the most sophisticated spyware ever deployed, including NSO Group’s Pegasus. “Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals,” said Adam Boynton, senior enterprise strategy manager at Jamf.

Apple’s advisory notes no confirmed exploitation in the wild for CVE-2026-65346. But cybercriminals will often try to reverse-engineer the patch to come up with an exploit once a fix is published — or the researchers who found it will post a proof-of-concept once everyone has had a chance to apply the update. The window between a patch dropping and an exploit being developed has compressed dramatically in recent years. The urgency is real.

The Other Flaws Worth Knowing About

CVE-2026-65346 is the headline, but it’s not the only serious issue in this update.

CVE-2026-65343 is a use-after-free that a remote attacker could use to cause unexpected system termination. CVE-2026-64788 is a memory corruption vulnerability triggered by maliciously crafted web content — it pairs a browser entry point with a graphics driver bug, creating a two-stage attack path.

Also worth prompt attention is CVE-2026-65329, a telephony issue affecting iPhones which could enable an attacker with network privileges to bypass IPSec authentication and snoop on network traffic. For anyone who travels and uses public Wi-Fi — especially without a VPN — that flaw is particularly relevant.

There’s also a previously patched flaw that’s now confirmed actively exploited. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-65400 to its Known Exploited Vulnerabilities catalogue. It is an improper authentication vulnerability that could allow a threat actor to authenticate to a device’s Screen Sharing feature without valid credentials. According to the Dutch National Cyber Security Centre, it has been used against multiple systems to obtain root access and install a Monero crypto miner.

Which Devices Are Affected

The ImageIO flaw affects a wide range of current Apple hardware. The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models.

Older devices running iOS 18 also receive a separate update. iOS 18.7.10 also includes CVE-2026-43818, an issue in ImageIO that could enable arbitrary code execution — so this isn’t just a concern for users on the latest software. Apple still ships fixes to the iOS 18, iOS 16 and iOS 15 branches for older hardware, though coverage narrows with each release. iOS 18.7.10 now covers only iPhone XS, iPhone XS Max, iPhone XR and the 7th-generation iPad.

In short: if you own an Apple device made in the last several years, you have an update waiting. Install it.

How to Update Right Now

On iPhone or iPad: open the Settings app, tap General, then Software Update. The update will be listed if you haven’t already installed it. Tap Download and Install.

On Mac: click the Apple menu, select System Settings, then General, then Software Update.

The update takes about ten minutes on most devices. If you’re concerned about timing, you can schedule it to install overnight. But don’t skip it and don’t delay it unnecessarily. Experts urged users to install the August 17 patches as soon as possible.

A Note on the Broader Pattern

This is the fourth significant Apple security update in 2026 addressing image-parsing or media-processing vulnerabilities. That’s not a coincidence. Image parsing is one of the most complex and attack-prone areas of any operating system — images can contain enormous amounts of data in formats that have evolved over decades, and parsing them correctly requires handling an enormous range of edge cases.

The fact that Meta’s Red Team X found this particular vulnerability is worth noting. Meta runs one of the most respected security research operations in the industry, and their teams regularly find serious flaws in competitors’ software — a practice that benefits the entire ecosystem when handled through responsible disclosure, as this was.

Apple fixed the flaw within its standard update cycle and credited the researcher. The system, in this case, worked. Your job is the last step: install the update. For more on protecting your devices against evolving threats, see our guide on protecting yourself from AI-powered cyber threats and our roundup of the worst cyberattacks and data breaches of 2026 so far.

The Bottom Line

A zero-click spyware-grade flaw in Apple’s image processing framework is exactly the kind of vulnerability that demands immediate action. Apple patched it on August 17. You should install that patch today — before the technical details required to exploit it become public knowledge.

Settings → General → Software Update. Ten minutes. Do it now.

Read more tech related articles here.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *