A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf
https://www.tenable.com/blog/cve-2023-41064-cve-2023-4863-cve-2023-5129-faq-imageio-webp-zero-days
https://support.apple.com/kb/HT213907
https://support.apple.com/kb/HT213905
https://support.apple.com/en-us/HT213907
https://support.apple.com/en-us/HT213905