Executive brief
A security vulnerability in Apple's mobile and desktop operating systems could allow an individual with physical access to a locked device to view sensitive user information. This affects iPhones, iPads, and Mac computers running older versions of their respective software. Users should update to the latest available versions to ensure their private data remains protected even if the device is lost or stolen.
Technical details
An out-of-bounds read vulnerability exists in multiple Apple operating systems due to insufficient bounds checking. An attacker with physical access to a locked device can exploit this flaw to bypass certain lock-screen protections and access sensitive user data. The issue was addressed by improving input validation and bounds checking in the affected components. Patches are available in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched