Executive brief
A security vulnerability exists in Apple's operating systems, including those for iPhone, Mac, and Apple Watch, which could allow a malicious app to crash the system or modify sensitive kernel memory. This flaw is being actively exploited in the wild, potentially allowing attackers to compromise the core security of the device. Users should update their devices to the latest software versions immediately to protect their data and system stability.
Technical details
A classic buffer overflow (CWE-120) exists in the kernel or a high-privilege component of multiple Apple operating systems due to improper memory handling. A local attacker can exploit this by running a malicious application on the target device to cause a denial-of-service (system crash) or perform unauthorized writes to kernel memory. This vulnerability is part of a known exploit chain and has been observed in active attacks. Apple addressed the issue by improving memory handling across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Affected products
- Apple iOS Before 18.7.2, 26.0 to 26.1
- Apple iPadOS Before 18.7.2, 26.0 to 26.1
- Apple macOS Sequoia Before 15.7.2
- Apple macOS Sonoma Before 14.8.2
- Apple macOS Tahoe Before 26.1
- Apple tvOS Before 26.1
- Apple visionOS Before 26.1
- Apple watchOS Before 26.1
Timeline
- 2026-03-20: disclosed
- 2026-03-20: kev added: Added to CISA KEV catalog due to active exploitation.
- 2026-03-20: patched: Fixes released in various OS updates including iOS 18.7.2 and macOS 15.7.2.