Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityendpoint-software-vulnerability

Apple Security Updates Address Multiple Vulnerabilities Including an In-the-Wild Exploited Memory Corruption Flaw

Updated 1mo agoFirst seen Feb 13, 20265 sources

Apple issued security updates across its ecosystem to address multiple vulnerabilities affecting iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, with impacts including remote code execution (RCE), denial of service, elevation of privilege, information disclosure, data manipulation, and security restriction bypass. HKCERT highlighted CVE-2026-20700 as a high-risk issue and noted it is being exploited in the wild; the flaw is described as an improper restriction of operations within the bounds of a memory buffer that could allow arbitrary code execution when an attacker has memory-write capability.

Apple’s iOS 26.3 and iPadOS 26.3 security content includes fixes for issues that could expose sensitive information on a locked device (e.g., CVE-2026-20645 and CVE-2026-20674) and a Bluetooth-related denial-of-service condition where a privileged network attacker could trigger DoS using crafted packets (CVE-2026-20650). The updates apply to iPhone 11 and later and a range of supported iPad models, and Apple reiterated its policy of publishing details after patches are available.

Share:
Apple Security Updates Address Multiple Vulnerabilities Including an In-the-Wild Exploited Memory Corruption Flaw
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 12, 20261mo ago

Apple patches macOS USD library flaw CVE-2026-28941

Apple released an update for CVE-2026-28941, an out-of-bounds read in the macOS USD library caused by improper validation of user-supplied data. ZDI said successful exploitation could disclose sensitive information with user interaction and noted the bug could be chained with other flaws; the issue was publicly disclosed as ZDI-26-315.

ZDI-26-315 | Zero Day Initiative

Apple patches macOS CoreSymbolication flaw CVE-2026-28918

Apple released an update to fix CVE-2026-28918, an out-of-bounds read in the CoreSymbolication framework on macOS caused by improper validation of user-supplied data. ZDI said the flaw could disclose sensitive information and potentially be chained with other bugs, and published coordinated advisory ZDI-26-311 on 2026-05-12.

ZDI-26-311 | Zero Day Initiative
Feb 13, 20264mo ago

HKCERT publishes bulletin on multiple Apple product vulnerabilities

HKCERT issued a security bulletin warning about multiple vulnerabilities affecting Apple products, reflecting and amplifying the vendor's February 2026 disclosures. The bulletin did not introduce a separate incident but documented the broader security impact for defenders.

Feb 11, 20264mo ago

Apple discloses targeted exploitation of CVE-2026-20627

In the iOS 26.3 and iPadOS 26.3 security advisory, Apple said it was aware of a report that CVE-2026-20627 may have been exploited in an "extremely sophisticated" targeted attack against specific individuals on iOS versions prior to iOS 26. Apple also said CVE-2025-14174 and CVE-2025-43529 were issued in response to that same report.

Apple releases iOS 26.3 and iPadOS 26.3 security updates

Apple published security updates for iPhone 11 and later and multiple iPad models, fixing numerous vulnerabilities affecting privacy, sandboxing, privilege escalation, memory safety, denial of service, and network security. The advisory also noted fixes for issues that could expose sensitive information on locked devices or enable arbitrary file writes, crashes, sandbox escape, or root privilege escalation.

Jan 22, 20242y ago

Apple patches CVE-2024-27791 in multiple operating systems

Apple addressed CVE-2024-27791, a high-severity out-of-bounds write in Apple PMP Firmware via the ApplePMPv2 writeDashboard interface, affecting iOS, iPadOS, macOS Monterey, macOS Ventura, macOS Sonoma, and tvOS before the January 22, 2024 fixes. The flaw could let an app corrupt Power Management Processor shared memory and trigger PMP panics, Data Aborts, SError exceptions, and ApplePMGR panics; Apple credited Pan Zhenpeng of STAR Labs SG and said it fixed the issue with improved validation.

(CVE-2024-27791) Apple PMP Firmware Out-of-Bounds Write via ApplePMPv2 writeDashboard | STAR Labs
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

67 LINKEDOpen in app
Vulnerabilities
44 linked
Out-of-bounds read in Apple CoreSymbolication file parsingApple dyld user-mode PAC bypass and memory corruptionCoprocessor Memory Corruption in Apple OSes (CVE-2024-27791)Denial of Service in Expat libexpat via excessive memory allocationOut-of-bounds memory access in ANGLE in Google Chrome on MacUse-after-free in Apple JavaScriptCore/WebKit leading to arbitrary code executionUntitledWebKit denial-of-service in Apple Safari, iOS, iPadOS, macOS, visionOS, WebKitGTK, and WPE WebKitLocal Privilege Escalation to root in Apple CoreServices (race condition)Sensitive screenshot exposure during iPhone Mirroring in iOS/iPadOS (UI state management)Arbitrary File Write in Apple CFNetworkApple Live Captions lock screen information disclosurePrivacy preferences bypass in Apple UIKit (CVE-2026-20606)Out-of-bounds access in Apple CoreAudio media file processing (CVE-2026-20611)CoreServices path-handling LPE to root (Apple platforms)Lock screen photo access via input validation issue in iOS/iPadOS PhotosSensitive data access via environment variable handling in Apple CoreServicesSensitive User Data Access in Apple Sandbox ProfilesGame Center Sensitive Information Disclosure via Insufficient Log RedactionIdentifying information leak to Live Caller ID app extensions in iOS/iPadOS (Call History)Kernel denial-of-service in Apple operating systemsSandbox bypass via symlink race condition in Apple Messages (Shortcuts)Information disclosure in Apple ImageIO via crafted image (bounds check issue)iOS/iPadOS VoiceOver lock-screen authorization bypass via state managementWebKit process crash on malicious web contentInformation disclosure in iOS/iPadOS Screenshots allows discovery of deleted NotesSensitive data access via directory-path parsing in Apple ShortcutsSafari Web Extensions User Tracking Privacy IssueSensitive data exposure via Spotlight app-state observability (CVE-2026-20680)Process memory disclosure in Apple ImageIO via crafted image parsingSandbox permissions issue leading to sandbox escape in Apple SandboxLock-screen information disclosure via inconsistent UI state management in iOS/iPadOS AccessibilityiOS/iPadOS LaunchServices logging sanitization flaw enabling installed-app enumerationTraffic interception (MITM) via logic issue in Apple Kernel/libnetcoreDoS in Apple Bluetooth via crafted packets (privileged network position)WebKit process crash on malicious web contentInstalled-app enumeration privacy issue in Apple StoreKitLocked-device sensitive information disclosure in iOS/iPadOS AccessibilityKernel memory corruption in Apple Wi‑Fi (CVE-2026-20621)CoreMedia memory disclosure and denial-of-service via crafted fileSandbox escape in Apple libxpc (CVE-2026-20667)WebKit process crash on malicious web contentWebKit process crash on maliciously crafted web contentOut-of-bounds read information disclosure in Apple Model I/O USD library
Affected products
13 linked
MacosIosIpad MiniTvosSafariMacos MontereyIpadosIpadMacos VenturaIphoneMacos SonomaMacIos
Organizations
10 linked
AppleTrend MicroSolidlabAisle ResearchRoute Zero SecurityBreakPoint.SHSTAR Labs SG Pte. LtdGoogleIruTrendAI Zero Day Initiative
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.