Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerability

Apple iOS/iPadOS Security Updates and CVE Fixes Across Multiple Releases

Updated 3mo agoFirst seen Jan 25, 202610 sources

Apple published security advisories detailing vulnerability fixes across multiple iOS and iPadOS versions, including iOS/iPadOS 16.7, 17.2, 18.1, 18.3, 26.1, and 26.2. The advisories describe a range of impacts such as sandbox escapes (including Web Content sandbox breakout), privacy issues where apps could access or expose sensitive user data via insufficient log redaction, file-system modification via temporary-file handling, and memory-safety flaws (e.g., out-of-bounds reads, type confusion, and bounds-checking issues) that could lead to crashes or memory corruption. Apple attributes fixes to changes like improved protocol handling, cache handling, input validation, and additional permission restrictions, and references issues by CVE where available.

Several advisories also highlight device-state and authentication/logic weaknesses: iOS/iPadOS 18.3 includes a case where an attacker with physical access to an unlocked device could access Photos while the app is locked (CVE-2025-24141), while iOS/iPadOS 18.1 includes a lock-screen exposure issue (CVE-2024-44274) and a Shortcuts-related path-handling flaw that could allow arbitrary shortcut execution without user consent (CVE-2024-44255). The iOS/iPadOS 26.x advisories include privacy and permission issues (e.g., identifying installed apps, screenshots of sensitive embedded views), potential kernel memory corruption/system termination conditions, and logic/UI issues affecting security posture (e.g., passcode requirement timing after Face ID enrollment restore scenarios and potential FaceTime caller ID spoofing), with multiple findings credited to external researchers and teams (including Google Project Zero, ByteDance IES Red Team, and others).

Share:
Apple iOS/iPadOS Security Updates and CVE Fixes Across Multiple Releases
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Jan 16, 20265mo ago

Apple publishes iOS 26.1 and iPadOS 26.1 security advisory

Apple published the iOS 26.1 and iPadOS 26.1 security advisory on January 16, 2026, documenting the vulnerabilities fixed in the November 2025 release and noting some entries had been updated on December 12, 2025.

Jan 9, 20266mo ago

Apple publishes iOS 26.2 and iPadOS 26.2 security advisory

Apple published the iOS 26.2 and iPadOS 26.2 security advisory on January 9, 2026, describing the December 2025 fixes and noting added or updated entries including a FaceTime caller ID spoofing issue and additional web-content crash vulnerabilities.

Dec 12, 20257mo ago

Apple releases iOS 26.2 and iPadOS 26.2

Apple released iOS 26.2 and iPadOS 26.2 on December 12, 2025, fixing numerous vulnerabilities including exposure of payment tokens, Safari history and hidden photos, file- and HID-triggered memory corruption, and a web-content flaw that may have been exploited in a highly targeted attack.

Nov 11, 20258mo ago

Apple publishes iOS 18.4, visionOS 2.4, and related security advisories

On November 11, 2025, Apple published security advisories for iOS 18.4 and iPadOS 18.4 as well as visionOS 2.4, detailing numerous fixes for privacy leaks, privilege escalation, sandbox escapes, local-network attack vectors, web spoofing, and memory-safety flaws.

Nov 4, 20258mo ago

Apple publishes iOS 26 and iPadOS 26 security advisory

Apple published the security advisory for iOS 26 and iPadOS 26 on November 4, 2025, later surfaced in the referenced support document, detailing numerous CVE-tracked vulnerabilities fixed in the September 2025 release.

Nov 3, 20258mo ago

Apple releases iOS 26.1 and iPadOS 26.1

Apple released iOS 26.1 and iPadOS 26.1 on November 3, 2025, addressing a broad set of privacy, permission-bypass, sandbox escape, keystroke monitoring, kernel memory corruption, and malicious web-content issues.

Sep 15, 20259mo ago

Apple releases iOS 26 and iPadOS 26

Apple released iOS 26 and iPadOS 26 on September 15, 2025, fixing numerous vulnerabilities including memory corruption, sensitive data exposure, sandbox bypasses, keystroke monitoring without permission, and web-content processing flaws.

Aug 20, 202510mo ago

Apple releases iOS 18.6.2 and iPadOS 18.6.2 for exploited image flaw

On August 20, 2025, Apple released iOS 18.6.2 and iPadOS 18.6.2 to fix CVE-2025-43300, an out-of-bounds write in image processing that could cause memory corruption. Apple said it was aware the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Jul 29, 202511mo ago

Apple publishes macOS Ventura 13.7.5 security advisory

Apple published the macOS Ventura 13.7.5 security update advisory on July 29, 2025, documenting numerous fixes for privilege escalation, sandbox escapes, authentication bypasses, privacy leaks, memory corruption, and network-reachable issues.

Apr 28, 20251y ago

Apple updates macOS Ventura 13.7.5 advisory with added CVEs

Apple added several CVE entries to the macOS Ventura 13.7.5 security advisory on April 28, 2025, with further updates on May 28, 2025 and an additional entry on July 29, 2025.

Apr 2, 20251y ago

Apple publishes iOS 18.2 and iPadOS 18.2 security advisory

Apple published the security advisory for iOS 18.2 and iPadOS 18.2 on April 2, 2025, detailing vulnerabilities fixed in the December 2024 release and noting several entries added or updated in early 2025.

Mar 3, 20251y ago

Apple publishes iOS 18 and iPadOS 18 security content advisory

Apple published the security content document for iOS 18 and iPadOS 18 on March 3, 2025, summarizing the vulnerabilities addressed in the September 2024 release and subsequent advisory updates.

Apple updates iOS 18 advisory with additional CVE entries

Apple added or updated multiple CVE entries in the iOS 18 and iPadOS 18 security advisory on October 28, 2024 and again on March 3, 2025, expanding the documented details of vulnerabilities fixed in the September 2024 release.

Dec 11, 20242y ago

Apple releases iOS 18.2 and iPadOS 18.2

Apple released iOS 18.2 and iPadOS 18.2 on December 11, 2024, fixing multiple issues including authentication bypasses, sandbox escapes, sensitive data exposure, network privacy weaknesses, and memory-safety flaws.

Sep 16, 20242y ago

Apple releases iOS 18 and iPadOS 18 security fixes

Apple released iOS 18 and iPadOS 18 on September 16, 2024, addressing numerous vulnerabilities affecting privacy, sandboxing, file handling, Bluetooth, VPN/networking, and web content processing on supported iPhones and iPads.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

200 LINKEDOpen in app
Vulnerabilities
133 linked
Wi-Fi Beacon Protection Bypass / Secure Network Disconnect in Apple platformsHeap-based buffer overflow in OpenEXR deep scanline parsingSensitive data exposure via insufficient permission restrictions in Apple OSes (CVE-2024-44184)Out-of-bounds Read in Apple file processingInstalled apps enumeration in iOS 18 / iPadOS 18Lock screen contacts disclosure in iOS/iPadOS (CVE-2024-44139)Cross-origin data exfiltration in Apple WebKit/Safari cookie managementAuthentication bypass allowing access to Private Browsing tabs in iOS/iPadOSScreen recording without indicator in iOS 18, iPadOS 18, and macOS Sequoia 15Arbitrary File Write via Race Condition in Apple archive unpackingInteger Overflow in Apple Web Content ProcessingUnexpected System Termination in Apple operating systemsSensitive User Information Leak in Apple iOS, iPadOS, macOS, and visionOSDenial-of-Service Logic Error in Apple OSesLock screen contact number disclosure in iOS/iPadOS/macOS (CVE-2024-44179)Kernel memory corruption / system termination in Apple OSes (iOS/iPadOS/macOS)Authentication bypass allowing access to Safari Private Browsing tabs (iOS/iPadOS)Unexpected app termination via out-of-bounds read in iOS/iPadOS (CVE-2024-27879)Heap corruption in Apple ARKit file processingLock-screen photo disclosure in iOS/iPadOS Assistive AccessProcess crash in Apple web content processingSandbox Escape in Apple LaunchServicesUnauthorized Local Network access in iOS/iPadOS (Local Network permission bypass)Lock Screen bypass in macOS Sidecar (state management issue)File access issue in Apple operating systems allowing access to user-sensitive dataApple private data redaction issue leaking contacts via log entries (CVE-2024-40791)Denial-of-service in iOS/iPadOS (fixed in iOS 18 / iPadOS 18)VPN traffic leak due to logic issue in Apple networking stack (iOS/macOS/visionOS)iOS/iPadOS lock screen contacts disclosure (CVE-2024-44180)Sensitive information disclosure in iOS/iPadOS (CVE-2024-40863)Unauthorized Bluetooth Access in Apple OSesSymlink validation issue leading to sensitive data access in Apple iOS/iPadOS/macOSArbitrary file overwrite in Apple platforms (iOS/iPadOS/macOS/visionOS)iOS/iPadOS Bluetooth pairing bypass via malicious input device (CVE-2024-44124)Authentication bypass in iOS/iPadOS Password Autofill (fills after failed authentication)Buffer overflow in Apple SceneKit file processingiOS/iPadOS/macOS Print Preview Temporary File Plaintext DisclosureSensitive data exposure in Apple OSes (iOS/iPadOS/watchOS/macOS)Siri lock-screen data exposure in iOS/iPadOS (CVE-2024-40840)Iframe sandbox policy bypass in Safari custom URL scheme handlingClickjacking leading to Photos library access prompt spoofing in iOS/iPadOS/macOSUniversal XSS in Apple Safari and Apple operating systems WebKitPrivacy bypass in Apple iOS/iPadOS/macOS allowing root app access to keyboard input and location without consentUnauthorized App Modification in Apple App ManagementOut-of-bounds image processing denial-of-service in Apple platformsiOS/iPadOS Accessibility Control Nearby Devices from Lock ScreenSiri Auto-Answer Bypass on Locked iOS DevicesWebKit array allocation sinking crash in Safari/WebKitGTK/WPE WebKitKernel passcode attempt delay logic issue in Apple operating systemsUser Fingerprinting Privacy Issue in iOS, iPadOS, and visionOSSensitive User Data Access in Apple Photos Temporary File HandlingSandbox restriction bypass in Apple ShortcutsAirPlay access control bypass allowing unauthenticated commands without pairingWebKit process crash on malicious web contentProcess crash in Apple WebKit web content processingAuthentication bypass in Apple Password AutoFillWebKit malicious web content Safari crash in Apple platformsType confusion in Apple AirPlay leading to app terminationMemory corruption in Apple WebKit web content processingSensitive user data exposure via logging in Apple BluetoothKernel UDP socket interface binding logic flaw in Apple operating systemsWebKit state management flaw causing process crash on malicious web contentSafari user interface spoofing via inconsistent UI state managementBuffer Overflow in Apple BiometricKitLock Screen Notification Content Disclosure in iOS and iPadOSOut-of-bounds access in Apple Audio media file processingRemote denial-of-service in Apple SecuritySensitive keychain data exposure from iOS backup in Apple AccountsProcess crash in WebKit from maliciously crafted web contentNegative length handling flaw in libexpat XML_ParseBufferASLR bypass via out-of-bounds access in Apple operating systemsSensitive User Data Exposure via Insufficient Log Redaction in Apple OSesOut-of-bounds read in Apple Audio allowing kernel memory disclosureOut-of-bounds access in Apple Model I/O media file processingCoprocessor Memory Corruption in Apple OSes (CVE-2024-54517)WebAuthn credential cross-origin claim in Apple Authentication ServicesKernel State Leak via Race Condition in Apple OSesApple AirPlay local network app termination vulnerabilityMemory corruption in Apple WebKit web content processingHeap-based Buffer Overflow in Apple Model I/O USD importMeshesWebKit memory corruption in Apple Safari and Apple platformsMemory corruption in Apple CoreMedia video file processingPrivilege Escalation in Apple Operating Systems (CVE-2024-44225)Out-of-bounds access in Apple Model I/O media file processingApple Account Fingerprinting via System BinarySensitive User Data Exposure via Logging in Apple FocusCoprocessor Memory Corruption in Apple OSes (CVE-2024-54522)DNS Query Leakage with Private Relay Enabled in Safari/WebKitPrivacy Preferences Bypass in Apple RepairKitInteger truncation memory corruption in SQLite aggregate query handlingSensitive User Data Exposure via Siri LoggingCross-origin data exfiltration in WebKitSymlink handling flaw in Apple libxpc leading to unauthorized file deletionProcess crash via malicious HID device in Apple macOS/iOS/iPadOSSensitive information exposure in Apple system loggingOut-of-bounds write in Apple IOHIDFamilyLock Screen Restricted Content Exposure in iOS/iPadOSInteger Overflow DoS in Apple AirPlayCoprocessor Memory Corruption in Apple OSes (CVE-2024-54523)Process Memory Disclosure in Apple libnetcore Web Content HandlingAddress Bar Spoofing in SafariSensitive user data access in Apple NotesOut-of-bounds access in Apple ImageIO media file processingLocal network app termination in Apple AirPlayLock Screen Notification Exposure in iOS/iPadOSOut-of-bounds access in Apple Model I/O media file processingOut-of-bounds read in Apple CoreText media file processingInformation Disclosure via System Logs in Apple Messages and MailSensitive Information Exposure via Insecure Network Transmission in iOS/iPadOSUser fingerprinting privacy issue in Apple Find MyMemory corruption in Apple CoreMedia video file processingSensitive Information Disclosure in Apple AirPlaySandbox Escape in Apple CalendarPassword Field Exposure in iOS and iPadOSProcess crash in Apple WebKit web content processingApple Mail remote content loading despite disabled Load Remote Images settingCross-origin data exfiltration in Apple iOS and iPadOSKernel memory corruption in Apple operating systemsKernel denial-of-service in Apple operating systemsKernel memory corruption in Apple Neural EnginePrivate Relay DNS Query Leak in Apple PlatformsWebKit malicious web content process crashOut-of-bounds access in libarchive RAR parserUnexpected URL Redirection in SafariSensitive Location Information Disclosure in Apple MapsSensitive Information Screenshot in Apple Embedded ViewsCloudKit symlink validation sandbox escapeDenial of service in iOS/iPadOS allowing unprivileged termination of root processesWebKit malicious web content Safari crashWebKit memory-handling flaw leading to process crash on crafted web contentSensitive User Data Access in Apple OSesUser fingerprinting issue in Apple InstallerSandbox Escape in Apple Operating Systems (CVE-2024-54468)
Affected products
15 linked
MacosIosIosIpadosIpad MiniSafariIpadIphoneShortcutsIosIphone 11Macos VenturaMacosChromeIos
Organizations
52 linked
Trend MicroAppleGoogleKandjiOligo SecurityShielderTikTokTashita Software SecurityBreakPoint.SHPixiePoint SecurityJamfMoveworksHakTrakOnymosOstorlabSuma Soft Pvt. Ltd.Deutsche Telekom Security GmbHZaprico DigitalSecuRingCyberservalZUSO ARTAlibaba CloudSupernetworksSafranMicrosoft CorporationGitHubDBAppSecurityRoute Zero SecurityTotally Not Malicious SoftwareTencentCisco SystemsLinkedinOffensive SecurityLoadshine LabJD.comParagonERPABC Research s.r.o.Trail of BitsLupus NovaBaiduTecnoStackhopper SecuritySolidlabfolivora.AI GmbHBest Buddy AppsZone MediaDragon Fruit Securitygrepular.comjakederouin.comREDTEAM.PLtheoffcuts.orgMysk
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.