Apple has fixed five issues in OS X and iOS that are very reminiscent of the famous Stagefright vulnerability found in Android devices and allowed attackers to completely compromise devices through a malicious image.
The vulnerability lies in the way Apple products process certain types of image files. Affected products include OS X, iOS, tvOS, and watchOS.
Tyler Bohan of the Cisco Talos team discovered the issues, which can be exploited by sending a modified image attached to an email message to victims, embedded in a web page, via iMessages, MMS messages, or all sorts of other applications.
The problem lies in the fact that some Apple products will attempt to automatically process the image they received from the attacker to create and display athumbnail.
When this happens, the Apple product loses control over how it should handle memory space and the malicious code embedded in the image will execute, allowing the attacker to take control of the device.
Even if remote code execution is performed within the privileges of the infected application, there are many local privilege escalation issues that can help attackers gain administrator privileges and then execute code with broader access, by adding the device to botnet or installing some additional intrusive malware.
As you can see, the basic theme and exploit chain for this bug is almost identical to Stagefright, a serious vulnerability discovered in the Android OS last August, which is why Google created the Android Security Bulletina month later.
According to technical report , the five issues found concern the way Apple software deals with TIFF images through the Image I/O component (CVE-2016-4631), how it deals with OpenEXR images through the Image I/O component (CVE-2016-4629, CVE-2016-4630), how it deals with DAE (Digital Asset Exchange) in Scene Kit and other applications (CVE-2016-1850), and finally, how it deals with BPM images through the Apple Core Graphics API (CVE-2016-4637).
Apple has released security updates to fix the aforementioned issues in iOS 9.3.3, tvOS 9.2.2, watchOS 2.2.2, and El Capitan v10.11.6. Other, unrelated security updates are also available for iTunes 12.4.2 for Windows and Safari 9.1.2.

