Executive brief
A race condition in Apple's operating system kernel can allow applications to trigger unexpected system crashes or corrupt critical kernel memory. This vulnerability affects iPhones, iPads, and Mac computers, and could lead to denial of service or potentially enable further attacks if kernel memory is successfully corrupted.
Technical details
A race condition vulnerability exists in the kernel state handling across Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS). The vulnerability is triggered when an app exploits a timing gap in state management, allowing concurrent access to shared kernel resources without proper synchronization. The flaw permits an app to cause unexpected system termination (denial of service) or corrupt kernel memory. No authentication is required beyond the ability to run an app on the device. Patches have been released across multiple OS versions including iOS 26.7/27, iPadOS 26.7/27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 26.7, 27
- Apple iPadOS before 26.7, 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched