Executive brief
A security issue in Apple operating systems could allow a remote attacker to bypass network filters. This affects a wide range of devices including iPhones, iPads, Macs, and Apple Watches. An exploit could allow unauthorized network traffic to reach the device or bypass security controls intended to restrict access. Apple has released software updates to address this by improving how the system manages its internal state.
Technical details
An inconsistent user interface vulnerability exists in multiple Apple operating systems due to improper state management. A remote attacker can exploit this flaw to bypass network filters. The vulnerability affects iOS, iPadOS, macOS (Sequoia, Sonoma, and Tahoe), tvOS, visionOS, and watchOS. Apple addressed the issue by improving state management within the affected components. Patches are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and corresponding versions for other platforms.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: advisory: Initial disclosure by Apple and NVD publication
- 2026-07-27: patched: Fixes released in various Apple OS updates