Executive brief
A vulnerability in the Accelerate framework across Apple operating systems could allow a malicious application to crash the system or specific services. This results in a denial-of-service, potentially disrupting user operations and device availability. Users are advised to update to the latest software versions to resolve this issue.
Technical details
An out-of-bounds read vulnerability exists in the Accelerate framework across multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS). The flaw is caused by insufficient bounds checking when processing data within the framework. A local application can exploit this vulnerability to trigger a denial-of-service (DoS) condition. Apple addressed the issue in version 26.5 of its various operating systems by implementing improved bounds checking.
Affected products
- Apple iOS Before 26.5
- Apple iPadOS Before 26.5
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory