Executive brief
Apple's iOS and iPadOS operating systems contain a buffer overflow vulnerability that can be exploited by an app to cause a denial of service, making the device temporarily unresponsive or forcing a restart. While not immediately exposing user data, this type of vulnerability could be chained with other exploits to achieve more serious compromise. Apple has released patches addressing this issue across multiple iOS and iPadOS versions.
Technical details
A buffer overflow vulnerability was identified in iOS and iPadOS that results from insufficient bounds checking during memory operations. An untrusted app with standard app sandbox permissions can trigger this vulnerability to cause a denial of service condition. The vulnerability does not allow arbitrary code execution or privilege escalation based on available information. Apple addressed the issue with improved bounds checking in iOS 18.7.10, iPadOS 18.7.10, iOS 27, and iPadOS 27. The attack vector is local (requires malicious app installation) with no additional privileges required beyond typical app permissions.
Affected products
- Apple iOS before 18.7.10 and before 27
- Apple iPadOS before 18.7.10 and before 27
Timeline
- 2026-09-14: disclosed