Executive brief
A security vulnerability exists in several Apple operating systems, including iOS, macOS, and watchOS. An attacker on the same local network as a vulnerable device could exploit this flaw to cause a system crash or service outage. This could disrupt business operations or personal use by forcing devices to restart or become unresponsive.
Technical details
An out-of-bounds write vulnerability exists across Apple's ecosystem due to insufficient bounds checking. The flaw allows an attacker situated on the same local network to trigger a denial-of-service (DoS) condition. The issue was addressed by improving input validation and bounds checking in the affected components. Patches are available in iOS 18.7.9, iOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, and corresponding versions of iPadOS, tvOS, visionOS, and watchOS.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory