Executive brief
A memory management flaw in Apple operating systems allows applications to trigger unexpected system termination or corrupt kernel memory through a double free vulnerability. This could enable attackers to cause denial of service or potentially achieve unauthorized access to sensitive system resources. The vulnerability affects iPhones, iPads, Macs, Apple TVs, Vision Pro devices, and Apple Watches.
Technical details
A double free vulnerability was identified in the memory management subsystem across multiple Apple platforms. The vulnerability allows an application to trigger unexpected process termination or potentially corrupt kernel memory by exploiting improper handling of freed memory regions. This is a local attack vector requiring the attacker to execute code on the device. The issue has been addressed with improved memory management across iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS prior to 26.7 and 27
- Apple iPadOS prior to 26.7 and 27
- Apple macOS Golden Gate prior to 27
- Apple macOS Sequoia prior to 15.8
- Apple macOS Tahoe prior to 26.7
- Apple tvOS prior to 27
- Apple visionOS prior to 27
- Apple watchOS prior to 27
Timeline
- 2026-09-14: disclosed: Security advisory published
- 2026-09-14: patched: Fixes available in iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27