Executive brief
A security vulnerability has been identified in various Apple operating systems, including iOS, macOS, and watchOS. A malicious application installed on a device could exploit this flaw to cause a sudden system crash or service interruption. This could disrupt operations and temporarily prevent users from accessing their devices or data.
Technical details
An out-of-bounds write vulnerability exists in the memory management components of multiple Apple operating systems. The flaw is caused by insufficient bounds checking when processing data, which can be triggered by a local application. An attacker could exploit this to cause a denial-of-service (DoS) by crashing the affected system or service. Apple has addressed this issue by implementing improved bounds checking in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Tahoe Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple: watchOS Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched