CVE-2026-65346
published 2026-08-17CVE-2026-65346: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.33%
26.3th percentile
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6.1 | 26.6.1 |
| apple | ipados | < 26.6.1 | 26.6.1 |
| apple | iphone_os | < 26.6.1 | 26.6.1 |
| apple | macos | < 26.6.2 | 26.6.2 |
| apple | macos | >= 26.0 < 26.6.2 | 26.6.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 integer overflow
vuldb·2026-08-18
CVE-2026-65346 Apple iOS/iPadOS/macOS prior 26.6.1/26.6.2 integer overflow
A vulnerability was found in Apple iOS, iPadOS and macOS. It has been classified as very critical. This affects an unknown function. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-65346. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
An integer overflow was addressed with improved input validation.
ghsa_unreviewed·2026-08-18
CVE-2026-65346 [HIGH] CWE-190 An integer overflow was addressed with improved input validation.
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
blogs_hackernews·2026-08-24
CVE-2026-19478 ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
## ⚡ Threat of the Week
U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series program
Sans Isc
Apple Patches iOS and macOS, (Mon, Aug 17th)
blogs_sans_isc·2026-08-17·CVSS 5.5
CVE-2026-28958 [MEDIUM] Apple Patches iOS and macOS, (Mon, Aug 17th)
Apple Patches iOS and macOS
Published: 2026-08-17. Last Updated: 2026-08-17 20:26:39 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone Safari patch for older operating systems. 87 of the vulnerabilities affect only iOS 18, making this more of an iOS 18 release than one for the newer operating systems. Only six vulnerabilities affect all three OSs released today. All 6 vulnerabilities affect WebKit.
Apple's
2026-08-17
Published