Skip to content

MacPublished 5 min read

macOS Tahoe 26.6.2 fixes CVE-2026-65346, an ImageIO code execution bug (August 17, 2026)

Illustration for the article “macOS Tahoe 26.6.2 fixes CVE-2026-65346, an ImageIO code execution bug (August 17, 2026)”
Listen to this article · 7:21 · AI-generated narration
0:00 / 7:21
Chapters

Why an ImageIO bug is worse than it sounds

ImageIO is the system framework that decodes image files, so it is not one application's problem. Apple's "Available for" line is simply macOS Tahoe, which means every Tahoe-capable Mac. The same decoder is reached by Preview, Photos, Mail, Messages and Finder thumbnailing, so the dangerous action is passive: an image that arrives and gets previewed is enough. There is no file to open and no button to press.

Apple gives the cause as "An integer overflow was addressed with improved input validation." The sibling ImageIO entry in the same release, CVE-2026-65347, is only a denial of service, described as "Processing an image may lead to a denial-of-service" and addressed with improved checks.

TL;DR

Apple released macOS Tahoe 26.6.2 on August 17, 2026, and its most serious entry is CVE-2026-65346, an ImageIO integer overflow whose impact Apple Support describes on August 17, 2026 as "Processing an image may lead to arbitrary code execution". The flaw sits in a system image decoder, so previewing or receiving a crafted image is the dangerous action, and there is no workaround short of updating. Nothing in this release is reported as exploited, and no matching update shipped for macOS Sequoia or macOS Sonoma.

  • macOS Tahoe 26.6.2 is build 25G83, roughly 2.9 GB on Apple silicon, and it needs a restart.
  • CVE-2026-65346 is an integer overflow in ImageIO, addressed with improved input validation.
  • A kernel entry, CVE-2026-65343, lets a remote attacker cause unexpected system termination.
  • No workaround exists: the vulnerable decoder is reached by Quick Look, Mail and Messages previews.
  • macOS Sequoia and macOS Sonoma got nothing on this date, which leaves them on older code.

What else is in the release

The kernel entry is the other one worth reading twice. CVE-2026-65343 has the impact "A remote attacker may be able to cause unexpected system termination", from a use-after-free addressed with improved memory management. There is also an Audio entry, CVE-2026-65339, where "An app may be able to leak sensitive user information", and an IOGPUFamily entry, CVE-2026-64788, where maliciously crafted web content may lead to memory corruption.

The counts differ depending on who is doing the counting. The Eclectic Light Company says on August 17, 2026 that the update addresses 20 vulnerabilities, while MacRumors the same day describes nearly 30 and references 29 CVEs in Apple's document, of which WebKit accounts for 21 and nine are credited to OpenAI Codex Security. Apple's own security note is the record. MacRumors adds that "None of the vulnerabilities are known to have been actively exploited", with the caveat that attackers can still go after devices left on earlier versions.

ComponentCVEImpact in Apple's words
ImageIOCVE-2026-65346Processing an image may lead to arbitrary code execution
ImageIOCVE-2026-65347Processing an image may lead to a denial-of-service
KernelCVE-2026-65343A remote attacker may be able to cause unexpected system termination
AudioCVE-2026-65339An app may be able to leak sensitive user information
IOGPUFamilyCVE-2026-64788Processing maliciously crafted web content may lead to memory corruption

What the update changes on the Mac itself

The build number is 25G83 and the download is roughly 2.9 GB on Apple silicon. Safari goes to 26.6.2 and the Passwords app to version 2.6.2. The update also raises firmware: mBoot to 18000.161.10 on Apple silicon, and iBridge to 23.16.16068.0.0,0 on Intel Macs. A firmware bump is the part you cannot interrupt, so leave the Mac alone while it restarts.

Older macOS lines were left where they were. The Eclectic Light Company notes that "There don't appear to any matching security updates to Sequoia or Sonoma, though", and MacRumors records that Apple shipped no macOS Sequoia or macOS Sonoma update on this date. MacRumors also points out that this was Apple's third security release in three weeks.

There is no workaround for this one

I usually have a stopgap to offer. Here there is none published, and I do not think an honest one exists. You cannot turn off the system image decoder, and you cannot practically avoid it: Quick Look, Mail and Messages previews and Finder thumbnails all run images through it in the ordinary course of using the Mac.

So the cost comparison is simple. Updating costs about 2.9 GB of download, a restart and a firmware write. Not updating leaves a code execution path that starts with an image someone sends you. On a Mac you depend on, take the restart.

What to do today

1. Open System Settings, go to General, then Software Update, and install macOS Tahoe 26.6.2.

2. Let it restart fully and do not cut the power during the restart, because this update writes firmware.

3. Confirm afterwards in System Settings, General, About that the version reads 26.6.2 and the build reads 25G83.

4. If you are on macOS Sequoia or macOS Sonoma, check Software Update anyway, and expect nothing for this batch on August 17, 2026.

5. Until the update is on, be careful with images from people you do not know, on the understanding that caution is not protection here.

Frequently asked questions

Do I have to open the image to be at risk?

No. The impact line is about processing an image, and processing happens when a preview or a thumbnail is generated. That is why the update is the only real answer.

Why did macOS Sequoia and macOS Sonoma get nothing?

Apple did not say. Both The Eclectic Light Company and MacRumors note the absence of matching updates on August 17, 2026, and MacRumors cautions that attackers can still go after devices left on earlier versions.

All articles