Executive brief
Apple has released security updates for various operating systems, including iOS, macOS, and watchOS, to address a vulnerability that could allow a malicious file to compromise a device. If a user opens a specially crafted file, an attacker could potentially crash applications or execute unauthorized code on the system. This could lead to a loss of data privacy, unauthorized access to device features, or a complete system takeover.
Technical details
An out-of-bounds write vulnerability exists across several Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is triggered when the system processes a maliciously crafted file, leading to memory corruption. An attacker can exploit this to achieve arbitrary code execution or cause a denial-of-service (app termination). Apple addressed the issue by removing the vulnerable code in the latest software updates. The attack vector is typically remote, requiring a user to open or preview a malicious file.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
- Apple watchOS < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched