Executive brief
A security vulnerability in Apple's mobile and desktop operating systems could allow a malicious 3D model file to leak sensitive information from a device's memory. This could potentially expose private data handled by other applications or system processes. Users should update to the latest software versions to protect their information.
Technical details
A buffer overflow vulnerability exists in the handling of 3D models across multiple Apple operating systems, including iOS, iPadOS, and macOS. The root cause is improper memory handling during the processing of 3D model files. An attacker could exploit this by providing a malicious 3D model, which, when processed by the system, results in the disclosure of process memory. This is an information disclosure vulnerability rather than remote code execution. Apple has addressed the issue by improving memory handling in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, and macOS Tahoe 26.6.
Affected products
- Apple iOS and iPadOS before 26.6
- Apple macOS Sequoia before 15.7.8
- Apple macOS Tahoe before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched