All incidents

Apple July 2026 security update patches ImageIO flaw (CVE-2026-43818)

vulnerabilityopenJul 28, 2026 — Jul 30, 2026
Apple July 2026 Patch Fixes 210 Flaws Including ImageIO Bug

APPLE has issued its July 2026 security update, resolving 210 distinct vulnerabilities across iOS, iPadOS, macOS, tvOS, watchOS, visionOS and Safari, a jump from the 37 flaws addressed the previous month. The release, detailed in the company’s advisory here, prioritises a high‑risk ImageIO bug that could allow arbitrary code execution when a malicious picture is processed.

The ImageIO flaw, tracked as CVE-2026-43818, carries a CVSS score of 8.8 and affects all recent Apple operating systems. An attacker who can supply a specially crafted image file can trigger a memory corruption that leads to arbitrary code execution with the privileges of the compromised application. Technical details of the issue are discussed in the ZDI review here.

Two other severe defects were also patched. CVE-2026-64747 in the AVEVideoEncoder subsystem scores 7.8 and lets an attacker execute code with kernel privileges by feeding a malformed video stream, potentially giving full control of the device. CVE-2026-64767 in the afpfs component scores 9.8 and permits remote kernel memory corruption through a specially crafted AFP packet, enabling privilege escalation without any user interaction. Further commentary on these issues appears in the Malwarebytes report here.

Apple has not observed any of these vulnerabilities being exploited in the wild, and no threat actors have been publicly linked to them. The breadth of the update, which touches Wi‑Fi drivers, WebKit, media frameworks and numerous file‑parsing libraries, illustrates the firm’s ongoing effort to shrink the attack surface across its entire ecosystem.

The jump from 37 patches in June to 210 in July highlights the growing complexity of Apple’s software stack and the increasing value of its devices as a target for sophisticated intruders who often chain multiple weaknesses together to achieve their goals. Defenders should also review any third‑party libraries that rely on ImageIO for similar flaws, as the flaw may be present in apps distributed outside the App Store.

Security teams should make the July updates a priority for all managed devices, using mobile device management or similar tools to enforce an installation deadline. Where immediate rollout is not feasible, administrators should at least enable automatic updates on user‑owned hardware and confirm that the installed build numbers correspond to those listed in the advisory here.

In addition to patching, defenders ought to monitor logs for unexpected crashes in ImageIO, AVEVideoEncoder or afpfs components and consider applying application‑control rules that block untrusted image or video files from reaching critical workstations until the updates are fully deployed.

Intelligence briefing updated Jul 30, 2026

CVE-2026-64767 9.8 CVE-2026-43818 8.8 CVE-2026-64747 7.8
Root sourcesupport.apple.com
Timeline Coverage

Swipe to explore timeline