Executive brief
A vulnerability in Apple's mobile and desktop operating systems could allow a malicious application to crash the device or gain unauthorized access to protected system memory. This could lead to a complete system failure or allow an attacker to bypass security protections to access sensitive data. Users should update to the latest software versions to resolve this risk.
Technical details
An input sanitization issue exists in the kernel-level components of iOS, iPadOS, and macOS Tahoe. A local malicious application can exploit this flaw to trigger an out-of-bounds write or similar memory corruption in kernel space. Successful exploitation can lead to a denial-of-service (system crash) or arbitrary kernel memory writes, potentially resulting in full system compromise or privilege escalation. The issue was addressed by improving input validation in iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2.
Affected products
- Apple iOS and iPadOS < 26.5.2
- Apple macOS Tahoe < 26.5.2
Timeline
- 2026-06-29: disclosed
- 2026-06-29: patched