Executive brief
A buffer overflow vulnerability in Apple's iOS, iPadOS, and macOS operating systems can be triggered when opening a specially crafted file, causing unexpected crashes. While the immediate impact is denial of service (app or system termination), buffer overflows are a common vector for more serious exploitation such as arbitrary code execution, though current evidence suggests this particular issue results in crashes only.
Technical details
A buffer overflow vulnerability exists in Apple's operating system file processing component, addressed through improved size validation. The vulnerability is triggered by processing maliciously crafted files and results in unexpected process or system termination. The attack vector is local (file opening) with no authentication required; an attacker need only trick a user into opening a malicious file. Apple addressed the issue across multiple OS versions (iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27) released on September 14, 2026. Patches are available in the mentioned releases.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
- Apple macOS before Golden Gate 27, Sequoia before 15.8, Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
Timeline
- 2026-09-14: disclosed: Vulnerability disclosed alongside iOS 27, iPadOS 27, and macOS Golden Gate 27 release
- 2026-09-14: patched: Patched in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27