Executive brief
A security vulnerability exists in the operating systems for Apple iPhones, iPads, Macs, and other devices that could allow a malicious actor to take control of the device. If exploited, an attacker could execute unauthorized commands, potentially leading to the theft of personal data or full system compromise. Apple has reported that this flaw has been used in highly targeted attacks against specific individuals.
Technical details
A memory corruption vulnerability (CWE-119) exists across multiple Apple operating systems due to improper state management. An attacker who already possesses local memory write capabilities can exploit this flaw to achieve arbitrary code execution. The vulnerability has been observed in the wild being used in sophisticated, targeted attacks. Apple addressed the issue by improving state management in the affected components. Patches are available in version 26.3 across all impacted platforms.
Affected products
- Apple iOS before 26.3
- Apple iPadOS before 26.3
- Apple macOS Tahoe before 26.3
- Apple tvOS before 26.3
- Apple visionOS before 26.3
- Apple watchOS before 26.3
Timeline
- 2026-02-11: disclosed: Initial disclosure by Apple
- 2026-02-12: advisory: NVD and CISA publication
- 2026-02-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-02-12: exploited: Confirmed exploitation in the wild against targeted individuals
- 2026-02-12: patched: Fixes released in version 26.3 for all platforms