Executive brief
A vulnerability in the core operating system of Apple devices could allow a malicious application to crash the system or modify protected kernel memory. This affects a wide range of devices including iPhones, iPads, and Macs. If exploited, an attacker could potentially gain deeper control over the device or disrupt its operations.
Technical details
An out-of-bounds write vulnerability exists in the Apple Kernel due to insufficient input validation. A local malicious application can exploit this flaw to trigger a system crash (denial-of-service) or perform unauthorized writes to kernel memory. The issue affects multiple Apple operating systems including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Apple has addressed the root cause by improving input validation mechanisms across the affected platforms. Security updates are available to mitigate this risk.
Affected products
- Apple iOS Earlier than 18.7.9, earlier than 26.5
- Apple iPadOS Earlier than 18.7.9, earlier than 26.5
- Apple macOS Sequoia Earlier than 15.7.7
- Apple macOS Sonoma Earlier than 14.8.7
- Apple macOS Tahoe Earlier than 26.5
- Apple tvOS Earlier than 26.5
- Apple visionOS Earlier than 26.5
- Apple watchOS Earlier than 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory