Executive brief
A security vulnerability in the core operating system of iPhones, iPads, and Macs could allow a malicious application to gain full administrative (root) control over the device. If exploited, an attacker could bypass standard security protections to access any data, modify system settings, or monitor user activity. Users should update their devices to the latest software versions to resolve this issue.
Technical details
An authorization vulnerability exists in the Apple Kernel due to improper state management. A local attacker can exploit this flaw by running a specially crafted application on an affected device to escalate privileges from a standard user or sandboxed app to root. The issue was addressed by improving how the kernel manages internal states during authorization checks. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory