Executive brief
Apple has released security updates for iOS, iPadOS, macOS, tvOS, and visionOS to address a vulnerability that could allow a remote attacker to crash applications or corrupt memory. This issue affects a wide range of Apple devices, potentially impacting system stability and security. Users are advised to update their devices to the latest available versions to mitigate these risks.
Technical details
This vulnerability is an out-of-bounds write (CWE-787) affecting multiple Apple operating systems. The root cause was insufficient bounds checking, which has been addressed in the latest updates. A remote attacker can exploit this flaw to trigger heap corruption or cause an application to terminate unexpectedly. The attack vector is network-based, though specific preconditions or required user interactions are not detailed in the advisory. Fixes are available in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.
Affected products
- Apple iOS Before 26.6
- Apple iPadOS Before 26.6
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
- Apple tvOS Before 26.6
- Apple visionOS Before 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched