Executive brief
A security vulnerability in the core operating system (Kernel) of Apple devices could allow a local user or a malicious application to crash the system or access restricted memory. This affects a wide range of Apple products including iPhones, iPads, and Macs. If exploited, it could lead to a complete system shutdown or the exposure of sensitive information stored in the system's protected memory area.
Technical details
A buffer overflow vulnerability exists in the Apple Kernel due to insufficient input validation. A local attacker or a malicious application running on the system can exploit this flaw to trigger a system crash (denial of service) or perform an out-of-bounds read to disclose sensitive kernel memory. The vulnerability was addressed by improving input validation across multiple Apple operating systems. Affected platforms include iOS/iPadOS (versions prior to 18.7.9 and 26.5), macOS Sequoia, Sonoma, and Tahoe, as well as tvOS, visionOS, and watchOS.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory