Executive brief
A security vulnerability in the core operating system of Apple devices could allow a malicious application to crash the system. This affects a wide range of devices including iPhones, iPads, Macs, Apple TVs, and Apple Watches. If exploited, the flaw could lead to unexpected system shutdowns, potentially disrupting operations or causing data loss.
Technical details
A race condition exists within the Apple Kernel component across multiple operating systems. The vulnerability was addressed by implementing additional validation logic to prevent concurrent access issues. An attacker-controlled application running locally on the device could exploit this race condition to trigger a kernel panic, leading to unexpected system termination (Denial of Service). The issue is resolved in iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, and watchOS 26.5.
Affected products
- Apple iOS 18.7.9, 26.5
- Apple iPadOS 18.7.9, 26.5
- Apple macOS Sequoia 15.7.7
- Apple macOS Sonoma 14.8.7
- Apple macOS Tahoe 26.5
- Apple tvOS 26.5
- Apple watchOS 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory