Executive brief
Apple has released security updates for iOS, iPadOS, macOS, tvOS, and visionOS to address a vulnerability that could allow a remote attacker to crash applications or corrupt system memory. This issue affects a wide range of Apple devices, including iPhones, iPads, Macs, and Apple TVs. Exploitation could lead to service disruptions or potentially allow for further unauthorized actions on the device.
Technical details
An integer overflow vulnerability exists in Apple's iOS, iPadOS, macOS, tvOS, and visionOS. The flaw was addressed through improved input validation. A remote attacker can exploit this issue to trigger unexpected application termination (denial of service) or heap corruption, which could potentially lead to arbitrary code execution. The vulnerability is fixed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.
Affected products
- Apple iOS and iPadOS < 26.6
- Apple macOS Sequoia < 15.7.8
- Apple macOS Sonoma < 14.8.8
- Apple macOS Tahoe < 26.6
- Apple tvOS < 26.6
- Apple visionOS < 26.6
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched