Executive brief
A vulnerability in Apple's operating systems could allow sensitive information to be leaked when the system processes a specially crafted contact file. This affects a wide range of devices including iPhones, iPads, Macs, and Apple Watches. An attacker could potentially gain access to private data if a user interacts with a malicious contact card.
Technical details
An information disclosure vulnerability exists in the way Apple operating systems handle contact data. The root cause is insufficient input validation or "checks" when processing contact files. An attacker can exploit this by providing a maliciously crafted contact, which, when processed by the system, leads to the leakage of sensitive data. The vulnerability is addressed through improved input validation checks. Affected platforms include iOS/iPadOS before 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, and macOS Tahoe, visionOS, and watchOS before version 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched