Executive brief
A memory handling vulnerability exists in several Apple operating systems, including iOS, macOS, and tvOS. An attacker on the same local network could exploit this flaw to cause a device to crash or become unresponsive, resulting in a denial-of-service. This could disrupt business operations or personal use of the affected Apple devices.
Technical details
A vulnerability classified as uncontrolled resource consumption (CWE-400) exists in multiple Apple operating systems due to improper memory handling. An attacker positioned on the same local network as the target device can exploit this issue to trigger a denial-of-service (DoS) condition. The root cause was addressed by Apple through improved memory management logic. The vulnerability affects various versions of iOS, iPadOS, macOS (Sonoma, Sequoia, and Tahoe), and tvOS. Patches are available in the latest software updates for each respective platform.
Affected products
- Apple iOS and iPadOS < 18.7.9, < 26.5
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.7
- Apple macOS Tahoe < 26.5
- Apple tvOS < 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory