Executive brief
A vulnerability in Apple's operating systems (iOS, iPadOS, and macOS) could allow a malicious file to crash an application. By tricking a user into opening a specially crafted file, an attacker can cause the affected app to terminate unexpectedly. This impact is primarily focused on service availability and the stability of the device's software.
Technical details
An out-of-bounds write vulnerability exists in multiple Apple operating systems, including iOS, iPadOS, and macOS. The issue stems from insufficient input validation during the parsing of specially crafted files. An attacker can exploit this by providing a malicious file to a vulnerable application, leading to memory corruption and subsequent application termination (Denial of Service). Apple has addressed the root cause by improving input validation across affected versions, including iOS 18.7.9, iOS 26.5, and various macOS releases.
Affected products
- Apple iOS 18.7.9, 26.5
- Apple iPadOS 18.7.9, 26.5
- Apple macOS Sequoia 15.7.7
- Apple macOS Sonoma 14.8.7
- Apple macOS Tahoe 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched