Executive brief
A vulnerability in Apple's operating systems could allow a malicious application to cause a sudden system crash or gain unauthorized access to sensitive kernel memory. This affects iPhones, iPads, Macs, and Apple Watches. If exploited, this could lead to a complete loss of device stability or the potential for an attacker to bypass security protections to access protected data.
Technical details
A race condition exists in the kernel state handling of multiple Apple operating systems, including iOS, iPadOS, macOS, and watchOS. The vulnerability is triggered by improper state management, which a locally installed malicious application can exploit to cause a denial-of-service (system termination) or achieve arbitrary kernel memory writes. Successful exploitation could lead to local privilege escalation or kernel-level code execution. Apple has addressed this issue by improving state handling in the affected components. Patches are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched