Executive brief
A vulnerability in the core operating system kernel of Apple devices could allow a malicious application to crash the system. This affects iPhones, iPads, and Mac computers, potentially leading to unexpected restarts and loss of unsaved data. Users are advised to update to the latest software versions to resolve this issue.
Technical details
An integer overflow vulnerability exists in the Apple Kernel across multiple operating systems (iOS, iPadOS, and macOS). The flaw is rooted in insufficient input validation, which can be triggered by a local application. Successful exploitation allows an attacker-controlled app to cause a kernel panic, leading to unexpected system termination (Denial of Service). Apple addressed the issue in iOS 18.7.9, iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5 by implementing improved input validation.
Affected products
- Apple iOS Before 18.7.9
- Apple iPadOS Before 18.7.9
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory