Executive brief
A race condition vulnerability in Apple's operating systems can cause apps to trigger unexpected system termination. The vulnerability affects iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. While not currently being exploited in the wild, the issue could allow an attacker to crash system processes and disrupt device functionality.
Technical details
This vulnerability is a race condition in state handling that was fixed with improved state management. The vulnerability allows an app to cause unexpected system termination. The race condition is network-unreachable and does not require special authentication or elevated privileges—any app running on an affected device can exploit it. The attack vector is local (malicious or compromised app), and the impact is denial of service through process termination. Apple patched this issue across iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27, released on September 14, 2026.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched