Executive brief
IOGPUFamily is a graphics processing framework used by Apple operating systems to handle GPU-related operations when users view web content and media. A vulnerability in this component allows maliciously crafted web pages to cause memory corruption, potentially leading to application crashes, data exposure, or unauthorized code execution on affected devices.
Technical details
The vulnerability is a memory handling flaw in Apple's IOGPUFamily component that is triggered when processing maliciously crafted web content. The root cause is insufficient memory handling in the GPU processing logic. The attack vector is network-based and requires only that a user visit or interact with a malicious website; no special privileges or user authentication is needed. An attacker can achieve memory corruption, which may lead to denial of service (application crash) or potentially arbitrary code execution. The issue was fixed in iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, and watchOS 27 through improved memory handling.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
- Apple macOS Tahoe before 26.6.2
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched