Executive brief
A vulnerability in Apple's operating systems could allow a malicious application to perform unauthorized actions or cause a system crash. This affects a wide range of devices including iPhones, iPads, Macs, and Apple Watches. If exploited, the flaw could lead to a denial-of-service, effectively making the device or specific applications unusable until restarted.
Technical details
A vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) that allows an application to cause a denial-of-service. The issue stems from insufficient checks that failed to prevent unauthorized actions. An attacker-controlled application could exploit this logic flaw to disrupt system availability or terminate processes. Apple addressed the root cause by implementing improved checks and validation logic. Patches were released on May 11, 2026, across all affected platforms.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory