Executive brief
Apple has released security updates for iOS, iPadOS, macOS, and visionOS to address a vulnerability triggered by processing specially crafted files. If a user opens a malicious file, it could cause applications to crash unexpectedly or lead to other stability issues. This affects a wide range of Apple devices including iPhones, iPads, Macs, and Vision Pro headsets.
Technical details
An improper input validation vulnerability (CWE-20) exists in multiple Apple operating systems when processing maliciously crafted files. The issue was addressed through improved input checks to prevent unexpected application termination. An attacker could exploit this by tricking a user into opening a specifically formatted file, potentially leading to a denial-of-service condition for the affected application. The vulnerability is fixed in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7/14.8.8, macOS Tahoe 26.5, and visionOS 26.5.
Affected products
- Apple iOS and iPadOS < 18.7.9, < 26.5
- Apple macOS < 14.8.7, < 14.8.8, < 15.7.8, < 26.5
- Apple visionOS < 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory