Executive brief
A security vulnerability has been identified across multiple Apple operating systems, including iOS, macOS, and watchOS. This flaw could allow a remote attacker to cause a device to crash or become unresponsive, leading to a denial of service. Users should update their devices to the latest software versions to maintain system stability and availability.
Technical details
A type confusion vulnerability (CWE-843) exists in multiple Apple operating systems due to insufficient validation of object types during processing. A remote attacker can exploit this flaw over a network without any user interaction or special privileges. Successful exploitation allows the attacker to trigger a denial of service (DoS) condition, causing the affected system to crash or hang. Apple addressed the root cause by implementing improved type checks. Patches are available in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Affected products
- Apple iOS and iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: advisory: Initial publication of the vulnerability details.
- 2026-07-27: other: Advisory updated by Apple to include additional affected macOS versions.