Executive brief
A memory management vulnerability exists in Apple's operating systems, including iOS, macOS, and tvOS. A malicious application installed on a device could exploit this flaw to cause the system to crash or terminate unexpectedly. This could lead to a loss of unsaved data or temporary disruption of device availability.
Technical details
A use-after-free (UAF) vulnerability exists in the memory management component of multiple Apple operating systems. The flaw is triggered when an application improperly handles memory references, potentially allowing a local malicious app to cause a kernel or system-level crash (denial of service). The vulnerability is addressed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 through improved memory handling logic. While the primary reported impact is system termination, UAF vulnerabilities can sometimes be leveraged for more complex exploitation depending on the specific memory context.
Affected products
- Apple iOS before 26.6
- Apple iPadOS before 26.6
- Apple macOS Sequoia before 15.7.8
- Apple macOS Tahoe before 26.6
- Apple tvOS before 26.6
- Apple visionOS before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched