Executive brief
A security vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a malicious application to access protected user data. This could lead to the exposure of private information stored on the device. Users should update their devices to the latest software versions to protect their data.
Technical details
A vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, visionOS, and watchOS) due to improper input sanitization. A malicious application installed on the device can exploit this flaw to bypass protections and access sensitive user data. The issue has been addressed in the latest updates by improving input validation mechanisms. The attack requires a malicious app to be present on the system, making the attack vector local. Patches are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: advisory: Initial disclosure by Apple and NVD publication.
- 2026-07-27: patched: Fixes released in various OS updates.