A researcher discovered a 0-click heap overflow vulnerability in Apple's EXR image parser running inside a privileged daemon, which fires automatically when an iMessage is received and bypasses BlastDoor sandboxing — no user interaction required. The bug was found by fuzzing EXR files and exploited through automatic image processing that occurs before the notification banner even appears.
Background
Zero-click vulnerabilities represent the highest tier of mobile exploits, famously used by Pegasus spyware to compromise devices without any user action. Apple's iMessage processes media content automatically via protected daemons outside the BlastDoor sandbox boundary.
- Source
- Lobsters
- Published
- Sep 28, 2026 at 07:32 AM
- Score
- 8.0 / 10