Executive brief
Apple has released security updates for iOS, iPadOS, and macOS to address a vulnerability where processing a specially crafted file could lead to a system crash or the exposure of private memory contents. This issue affects iPhones, iPads, and Mac computers, potentially allowing an attacker to disrupt operations or gain access to sensitive information stored in the device's memory. Users are advised to update their devices to the latest software versions to mitigate these risks.
Technical details
A vulnerability exists in multiple Apple operating systems (iOS, iPadOS, and macOS) due to insufficient validation when processing crafted files. While the specific component is not explicitly named in the brief description, the vulnerability allows for denial-of-service (app or system termination) and potential disclosure of memory contents. The root cause was addressed by Apple through improved checks and memory handling. An attacker could exploit this by enticing a user to open a maliciously crafted file, requiring no special privileges. Patches are available in iOS/iPadOS 18.7.9, macOS Sequoia 15.7.7, and macOS Tahoe 26.5.
Affected products
- Apple iOS Before 18.7.9
- Apple iPadOS Before 18.7.9
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory