Executive brief
iOS and iPadOS are Apple's mobile operating systems used by hundreds of millions of users worldwide. A remote attacker can trigger a denial-of-service condition by sending maliciously crafted input, causing the device to become unresponsive or crash. Apple has patched this issue in iOS 27 and iPadOS 27.
Technical details
This is a denial-of-service vulnerability in iOS and iPadOS caused by insufficient input validation. A remote attacker can craft malicious input that bypasses validation checks and triggers unexpected process termination or system instability. The vulnerability is network-reachable and does not require user authentication or device-level privileges. Apple addressed the issue by implementing improved input validation logic in iOS 27 and iPadOS 27, released on September 14, 2026.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: iOS 27 and iPadOS 27 released