Executive brief
A race condition in how iOS and iPadOS handle symbolic links allows a malicious shortcut to bypass the sandbox restrictions that normally isolate apps from accessing sensitive system resources. An attacker could exploit this to gain unauthorized access to files and data that should be protected, potentially compromising user privacy and device security.
Technical details
This vulnerability is a race condition in the handling of symbolic links within iOS and iPadOS kernel or system framework components. The race condition occurs when the OS checks permissions on a file path and then accesses it; an attacker can exploit the window between these two operations by swapping a regular file with a symbolic link pointing to a protected location. The attack is delivered via a malicious shortcut (an iOS automation feature), which runs within a sandboxed environment but can leverage this race condition to bypass sandbox restrictions. This allows the shortcut to access files and resources outside its normal permission boundary. The vulnerability affects iOS 18.7.5 and earlier, iPadOS 18.7.5 and earlier, iOS 26.3 and earlier, iPadOS 26.3 and earlier, macOS Sequoia 15.7.4 and earlier, macOS Sonoma 14.8.4 and earlier, macOS Tahoe 26.3 and earlier, and visionOS 26.3 and earlier. Patches are available in the February 11, 2026 security updates.
Affected products
- Apple iOS before 18.7.5 and before 26.3
- Apple iPadOS before 18.7.5 and before 26.3
- Apple macOS Sequoia before 15.7.4
- Apple macOS Sonoma before 14.8.4
- Apple macOS Tahoe before 26.3
- Apple visionOS before 26.3
Timeline
- 2026-02-11: disclosed: Published by Apple on February 11, 2026
- 2026-02-11: patched: Fixed in iOS 18.7.5, iPadOS 18.7.5, iOS 26.3, iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3