Executive brief
A security vulnerability in Apple's operating systems could allow a malicious file to crash applications or run unauthorized code. This affects iPhones, iPads, and Mac computers when they process a specially crafted file. Users should update to the latest software versions to protect their devices and data from potential compromise.
Technical details
A buffer overflow vulnerability exists in Apple iOS, iPadOS, and macOS due to insufficient bounds checking when processing files. An attacker can exploit this by tricking a user into opening a maliciously crafted file, potentially leading to arbitrary code execution or a denial-of-service (app termination). The issue was addressed by improving bounds checking in the affected components. The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Tahoe < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched