Executive brief
A security vulnerability exists in several Apple operating systems, including iOS, macOS, and tvOS. A remote attacker could exploit this flaw to cause applications to crash unexpectedly or corrupt system memory. This could lead to service disruptions or potentially allow for further unauthorized actions on the device.
Technical details
A buffer overflow vulnerability exists in multiple Apple operating systems due to insufficient bounds checking. The issue affects iOS and iPadOS, macOS (Sequoia and Tahoe), tvOS, and visionOS. A remote attacker can exploit this vulnerability to trigger an application crash (denial of service) or cause heap corruption, which may lead to arbitrary code execution. Apple has addressed this vulnerability by improving bounds checking in the affected components. Patches are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched