ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability
Published Jul 29, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.
Affected Software
1 affected component
Apple macOS
Event History
Jul 29, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-492?
The severity of ZDI-26-492 is rated at 7.8 on the CVSS scale.
2
How do I fix ZDI-26-492?
To fix ZDI-26-492, update your Apple macOS to the latest version that addresses this vulnerability.
3
What does ZDI-26-492 affect?
ZDI-26-492 affects the ImageIO library in Apple macOS installations.
4
What type of vulnerability is ZDI-26-492?
ZDI-26-492 is a numeric truncation remote code execution vulnerability.
5
Who can exploit ZDI-26-492?
Remote attackers can exploit ZDI-26-492 by interacting with the ImageIO library on affected systems.