Executive brief
A vulnerability in Apple's mobile and desktop operating systems could allow a malicious application to crash the device or corrupt sensitive system memory. This affects iPhones, iPads, and Mac computers. If exploited, this could lead to a complete system failure or allow an attacker to gain deeper control over the device's core functions.
Technical details
A vulnerability exists in the kernel of Apple iOS, iPadOS, and macOS Tahoe due to insufficient input validation. A malicious local application can exploit this flaw to cause unexpected system termination (denial of service) or corrupt kernel memory. Memory corruption at the kernel level can potentially be leveraged for local privilege escalation. The issue was addressed by Apple through improved input validation in the affected components. Patches are available in iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple iOS and iPadOS before 26.5.2
- Apple macOS Tahoe before 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched