Back to search

Apple

iOS

Apple operating system for iPhone.

Current version
Last checked: 2026-09-05

16.7.16

Release date
May 11, 2026
Security status
Current version appears affected by 100 high-severity CVEs.

Source

endoflife.date

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
16.7.16 2026-05-11 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-43670 HIGH (8.8) 2026-08-25 Current versionaffected

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43794 HIGH (8.8) 2026-08-17 Current versionaffected

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6.1
CVE-2026-65346 HIGH (8.8) 2026-08-17 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead to arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6.1
CVE-2026-65343 HIGH (7.5) 2026-08-17 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A remote attacker may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6.1
CVE-2026-43757 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-43805 CRITICAL (9.8) 2026-07-27 Current versionaffected

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43813 HIGH (7.1) 2026-07-27 Current versionaffected

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64740 CRITICAL (9.3) 2026-07-27 Current versionaffected

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43673 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64783 HIGH (8.8) 2026-07-27 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43809 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-43799 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43776 HIGH (7.8) 2026-07-27 Current versionaffected

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64716 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64700 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64757 HIGH (8.8) 2026-07-27 Current versionaffected

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64720 CRITICAL (9.8) 2026-07-27 Current versionaffected

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43812 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64746 CRITICAL (9.8) 2026-07-27 Current versionaffected

An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43730 CRITICAL (9.8) 2026-07-27 Current versionaffected

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-28931 HIGH (8.8) 2026-07-27 Current versionaffected

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64766 HIGH (7.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43803 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64770 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64726 CRITICAL (9.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64771 CRITICAL (9.8) 2026-07-27 Current versionaffected

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43814 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43802 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-43711 HIGH (7.8) 2026-07-27 Current versionaffected

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43818 HIGH (8.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-28896 HIGH (7.7) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected system termination or read kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 26.4
CVE-2026-43822 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64747 HIGH (7.8) 2026-07-27 Current versionaffected

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64751 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64729 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64768 HIGH (8.1) 2026-07-27 Current versionaffected

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64695 CRITICAL (9.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-64713 HIGH (8.1) 2026-07-27 Current versionaffected

This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64725 HIGH (7.1) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64772 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-39877 HIGH (7.8) 2026-07-27 Current versionaffected

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-64764 HIGH (7.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43769 CRITICAL (9.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64733 CRITICAL (9.8) 2026-07-27 Current versionaffected

This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-28973 HIGH (8.6) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64749 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64765 HIGH (7.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43729 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. Processing a maliciously crafted image may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-28928 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43733 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64769 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64774 CRITICAL (9.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43807 CRITICAL (9.8) 2026-07-27 Current versionaffected

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-64762 CRITICAL (9.8) 2026-07-27 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-43780 HIGH (7.8) 2026-07-27 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64719 HIGH (8.1) 2026-07-27 Current versionaffected

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64758 HIGH (7.8) 2026-07-27 Current versionaffected

The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64739 HIGH (8.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64738 CRITICAL (9.8) 2026-07-27 Current versionaffected

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
CVE-2026-64692 HIGH (7.1) 2026-07-27 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43723 HIGH (7.8) 2026-07-27 Current versionaffected

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64763 HIGH (7.8) 2026-07-27 Current versionaffected

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43810 CRITICAL (9.8) 2026-07-27 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-64775 CRITICAL (9.8) 2026-07-27 Current versionaffected

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-43778 CRITICAL (9.8) 2026-07-27 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.6
CVE-2026-39868 CRITICAL (9.1) 2026-06-29 Current versionaffected

This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43701 HIGH (7.1) 2026-06-29 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43731 HIGH (8.8) 2026-06-29 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43724 HIGH (7.8) 2026-06-29 Current versionaffected

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43705 HIGH (8.8) 2026-06-29 Current versionaffected

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43725 HIGH (7.1) 2026-06-29 Current versionaffected

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43735 HIGH (8.1) 2026-06-29 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2026-43715 HIGH (8.8) 2026-06-29 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5.2
CVE-2025-46311 HIGH (7.5) 2026-05-12 Current versionaffected

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.3
  • From (including) 0 - Up to (excluding) 26.2
CVE-2026-28872 HIGH (7.5) 2026-05-11 Current versionaffected

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.4
CVE-2026-28995 HIGH (8.8) 2026-05-11 Current versionaffected

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28983 HIGH (7.5) 2026-05-11 Current versionaffected

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28940 HIGH (8.8) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28941 HIGH (7.1) 2026-05-11 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
CVE-2026-43668 HIGH (7.5) 2026-05-11 Current versionaffected

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28936 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Sonoma 14.8.8, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28873 HIGH (7.5) 2026-05-11 Current versionaffected

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.4
CVE-2026-28907 HIGH (8.1) 2026-05-11 Current versionaffected

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43655 HIGH (7.3) 2026-05-11 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43654 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28951 HIGH (7.8) 2026-05-11 Current versionaffected

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28906 HIGH (7.5) 2026-05-11 Current versionaffected

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able to track users through their IP address.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28947 HIGH (8.8) 2026-05-11 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43658 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28952 HIGH (7.5) 2026-05-11 Current versionaffected

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
CVE-2026-28905 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-43661 HIGH (7.5) 2026-05-11 Current versionaffected

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.10
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28913 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28944 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28987 HIGH (7.5) 2026-05-11 Current versionaffected

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28991 HIGH (7.5) 2026-05-11 Current versionaffected

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28929 HIGH (7.5) 2026-05-11 Current versionaffected

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.9
CVE-2026-28883 HIGH (7.5) 2026-05-11 Current versionaffected

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28964 HIGH (7.5) 2026-05-11 Current versionaffected

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.

Affected versions
  • From (including) 0 - Up to (excluding) 26.5
CVE-2026-28860 HIGH (7.5) 2026-05-11 Current versionaffected

The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.

Affected versions
  • From (including) 0 - Up to (excluding) 18.7.7
  • From (including) 0 - Up to (excluding) 26.4

268 further matching CVEs are not displayed. The table shows the 100 most relevant of 368, recently published first.