Executive brief
A memory corruption vulnerability exists in the IOHIDFamily component of various Apple operating systems, including iOS, macOS, and iPadOS. This component handles human interface devices like keyboards and mice. An attacker could exploit this flaw to cause applications to crash unexpectedly, potentially disrupting business operations or user productivity.
Technical details
A memory corruption vulnerability exists in the IOHIDFamily component of Apple operating systems due to improper locking mechanisms. The flaw can be triggered by an attacker to cause unexpected application termination (denial-of-service). The root cause was addressed by implementing improved locking logic within the component. The vulnerability affects a wide range of Apple platforms including iOS, iPadOS, macOS (Tahoe, Sequoia, Sonoma), tvOS, visionOS, and watchOS. Patches are available in the latest software updates released in May 2026.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory