Executive brief
iOS and iPadOS are Apple's mobile operating systems that power iPhones and iPads. An installed app can exploit an out-of-bounds memory read in the kernel to cause the device to crash unexpectedly or access sensitive kernel memory. This could enable attackers to bypass security protections or gain information about system internals.
Technical details
The vulnerability is an out-of-bounds read in the iOS/iPadOS kernel component that was addressed with improved input validation. An app with local access can trigger this issue to read memory outside intended bounds. The flaw allows an attacker to cause unexpected system termination (denial of service) or potentially leak kernel memory contents. Attack requires malicious app execution on the device; it is fixed in iOS 26.6.1, iPadOS 26.6.1, and corresponding versions of macOS (Tahoe 26.6.2, Sequoia 15.8), tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS 26.6.1 and later
- Apple iPadOS 26.6.1 and later
- Apple macOS Tahoe 26.6.2 and later
- Apple macOS Sequoia 15.8 and later
- Apple tvOS 27 and later
- Apple visionOS 27 and later
- Apple watchOS 27 and later
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched