Apple reportedly fixed CVE-2026-86869, dubbed EX-ARRR, a zero-click vulnerability in the libAppleEXR image decoder affecting iOS, iPadOS, and macOS 27. A crafted RGB OpenEXR (.exr) image can trigger a heap overflow when the decoder allocates 12 bytes per pixel but writes four-channel RGBA data at 16 bytes per pixel, creating a controlled linear overwrite.
An attacker could deliver the malicious EXR file through iMessage without requiring the recipient to open it: background photo-library indexing and thumbnail processing can decode the attachment after delivery. The reported processing path occurs in a separate daemon and may therefore fall outside BlastDoor’s protections. Researchers reported deterministic heap corruption, arbitrary-write capability, and program-counter control in a controlled harness, although Pointer Authentication and hardware memory tagging may complicate exploitation on newer Apple hardware. Organizations should prioritize the September 2026 Apple updates, as unpatched devices remain exposed.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Apple fixed CVE-2026-86869 across iOS, iPadOS, and macOS 27. The issue could allow a crafted EXR attachment to reach vulnerable ImageIO processing through background iMessage attachment indexing and thumbnail workflows without recipient interaction.
Apple received the vulnerability report, reproducer, crafted EXR files, and on-device crash artifacts. Apple Security reportedly classified it as 0-click code execution via an iMessage EXR image payload.
The researcher identified the libAppleEXR vulnerability through LLM-guided, disassembly-anchored fuzzing. The flaw is a controlled heap overflow caused by writing four RGBA channels into a buffer allocated for three RGB channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.