Executive brief
A vulnerability exists in the Apple File System (APFS) component used across iPhones, iPads, and Macs. A malicious application installed on the device could exploit this flaw to cause the entire system to crash or shut down unexpectedly. This could lead to data loss or disruption of operations for users and organizations relying on these devices.
Technical details
A buffer overflow vulnerability exists in the Apple File System (APFS) component due to insufficient bounds checking. A local attacker, via a malicious application, can exploit this flaw to trigger a system-wide denial-of-service (unexpected system termination). The issue affects a wide range of Apple platforms including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Apple has addressed the vulnerability by implementing improved bounds checking in the affected code paths. Patches are available in iOS 18.7.9, iOS 26.5, macOS Tahoe 26.5, and other concurrent security updates.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory