Executive brief
A memory management vulnerability in Apple's operating systems could allow a malicious application to crash the device. This affects a wide range of Apple products including iPhones, iPads, Macs, and Apple Watches. While primarily a stability risk, such flaws can sometimes be used to disrupt operations or facilitate further attacks.
Technical details
A use-after-free vulnerability exists in the IOKit component of multiple Apple operating systems. The flaw is rooted in improper memory management during object lifecycle handling. A local attacker, via a malicious application, can trigger this condition to cause a kernel-level crash or unexpected system termination. Apple addressed the issue by improving memory management logic. Affected platforms include iOS, iPadOS, macOS (Tahoe, Sequoia, Sonoma), tvOS, visionOS, and watchOS.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory