针对 ImageIO 中整数溢出漏洞的 PoC,该漏洞已在 iOS/macOS 26.5 中修复 (CVE-2026-28990)
漏洞发现者:Jiri Ha 和 Arni Hardarson
在 iOS/macOS 26.5 之前,函数 EXRReadPlugin::decodeBlockAppleEXR 在计算缓冲区大小时存在整数溢出漏洞。
通过使提供的图像的 width 和 height 值相乘后环绕到 0,然后以非常小的尺寸调用 malloc_type_malloc,可能导致内存破坏。
提供包含多余像素数据的图像文件会导致堆溢出和崩溃:
thread #5, queue = 'com.apple.root.user-interactive-qos', stop reason = EXC_GUARD (code=1, subcode=0x4141414141414151)
frame #0: 0x00000001855ba8c8 libdispatch.dylib`_dispatch_root_queue_drain + 176
libdispatch.dylib`_dispatch_root_queue_drain:
-> 0x1855ba8c8 <+176>: ldr x8, [x0, #0x10]!
0x1855ba8cc <+180>: cbz x8, 0x1855bab2c ; <+788>
0x1855ba8d0 <+184>: str x8, [x20, #0x68]
0x1855ba8d4 <+188>: mov x0, x20
Target 0: (exr_parser) stopped.