Executive brief
A security vulnerability has been identified in various Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This flaw could allow a malicious application to cause other apps to crash or terminate unexpectedly. Apple has released software updates to address this issue by improving how the systems handle memory boundaries.
Technical details
An out-of-bounds write vulnerability exists in multiple Apple operating systems due to insufficient bounds checking. An attacker, likely through a malicious application, could exploit this flaw to write data outside of allocated memory buffers. The primary impact identified is the ability to cause unexpected application termination (denial of service). Apple addressed the root cause by implementing improved bounds checking in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
Affected products
- Apple iOS and iPadOS Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
- Apple watchOS Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched