Executive brief
A security vulnerability in Apple operating systems, including iOS, macOS, and watchOS, could allow a malicious application to gain full administrative (root) control over a device. This level of access would allow an attacker to bypass security protections, access sensitive user data, or modify system settings. Users should update their devices to the latest software versions to resolve this issue.
Technical details
A path handling vulnerability exists across multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient validation of file paths. A local malicious application can exploit this flaw to escalate its privileges to root. The vulnerability was addressed by implementing improved path validation logic. Affected versions include iOS/iPadOS before 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and other platform versions prior to 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched