ZDI-CAN-29252: ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction with the ImageIO library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-43780.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29252?
The severity of ZDI-CAN-29252 is rated at 7.8 according to the CVSS.
How does ZDI-CAN-29252 affect Apple macOS?
ZDI-CAN-29252 allows remote attackers to execute arbitrary code on affected installations of Apple macOS through the ImageIO library.
What should users do to mitigate ZDI-CAN-29252?
Users should update their Apple macOS systems to the latest version that addresses the vulnerabilities in the ImageIO library.
Can ZDI-CAN-29252 be exploited remotely?
Yes, ZDI-CAN-29252 can be exploited remotely by interacting with the ImageIO library.
What versions of Apple macOS are affected by ZDI-CAN-29252?
All installations of Apple macOS that utilize the ImageIO library are potentially affected by ZDI-CAN-29252.