Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityopen-source-dependency-vulnerability

Apple Fixes Broad Set of iOS, macOS, and visionOS Vulnerabilities

Updated 1mo agoFirst seen Mar 26, 202665 sources

Apple released a wide-ranging set of security updates across iOS, iPadOS, macOS Tahoe, watchOS, tvOS, visionOS, Safari, and Xcode, addressing more than 85 vulnerabilities across core components including the kernel, WebKit, AirPlay, Keychain, and open-source libraries. The updates fix issues that could enable traffic interception, kernel state disclosure, user fingerprinting, installed-app enumeration, Mail privacy bypasses, exposure of deleted Notes content, and crashes from out-of-bounds writes. Apple said it had no reports of in-the-wild exploitation for the vulnerabilities listed in the release notes, but urged users to update, with particular importance for older devices and managed macOS environments.

Among the patched flaws is CVE-2024-27828, a high-severity memory-handling bug in IOSurfaceRoot that could let a local app trigger a kernel panic or execute arbitrary code with kernel privileges. STAR Labs said the issue stemmed from a reference count leak in IOSurfaceRootUserClient::s_create_shared_event, where repeated calls with crafted input could corrupt memory handling; the flaw affected iOS and iPadOS before 17.5, tvOS before 17.5, watchOS before 10.5, and visionOS before 1.2. Apple addressed the bug through improved memory handling, adding it to a broader pattern of fixes spanning both current and legacy Apple platforms.

Share:
Apple Fixes Broad Set of iOS, macOS, and visionOS Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

32 events from the most recent confirmed update back to the earliest known activity.

32 EVENTS
May 15, 20261mo ago

Apple releases Safari 26.5 for macOS with 11 security fixes

Apple released Safari 26.5 for macOS 15 Sequoia and macOS 14 Sonoma, addressing 11 security vulnerabilities that had previously been fixed in other recent updates. Apple said the flaws were not known to have been exploited in the wild.

Safari 26.5 - TidBITS
May 11, 20262mo ago

Apple publishes tvOS 26.5 security advisory

Apple released tvOS 26.5 and published its security-content advisory for Apple TV HD and Apple TV 4K models. The update addressed numerous vulnerabilities across sandboxing, kernel memory protections, media parsing, web content handling, networking, and system stability, with credits to researchers including Google TAG, Google Project Zero, ZDI, and STAR Labs SG.

About the security content of tvOS 26.5 - Apple Support

Apple publishes macOS Sonoma 14.8.7 security advisory

Apple published the security-content advisory for macOS Sonoma 14.8.7, detailing numerous fixes across kernel components, sandboxing, privacy controls, media parsing, networking, Gatekeeper, Mail Lockdown Mode, and user-consent protections. The update addressed risks including kernel-level code execution, privilege escalation, sandbox escape, denial of service, Gatekeeper bypass, and unauthorized access to sensitive user data.

About the security content of macOS Sonoma 14.8.7 - Apple Support

Apple publishes iOS 18.7.7 and iPadOS 18.7.7 security update

Apple released iOS 18.7.7 and iPadOS 18.7.7 and published the corresponding security-content advisory. This was a distinct security update for the 18.x branch issued on the same day as Apple’s broader 26.5 release wave.

About the security content of iOS 18.7.7 and iPadOS 18.7.7 - Apple Support

Apple publishes iOS 15.8.8 and iPadOS 15.8.8 security update

Apple released iOS 15.8.8 and iPadOS 15.8.8 and published the corresponding security-content advisory. This was a distinct security update for the 15.x branch issued on the same day as Apple’s broader 26.5 release wave.

About the security content of iOS 15.8.8 and iPadOS 15.8.8 - Apple Support

Apple publishes iOS 18.7.3 and iPadOS 18.7.3 security update

Apple released iOS 18.7.3 and iPadOS 18.7.3 and published the corresponding security-content advisory. This was a separate security update for the 18.x branch issued the same day as Apple’s broader 26.5 release wave.

About the security content of iOS 18.7.3 and iPadOS 18.7.3 - Apple Support

Apple releases iOS, macOS, and iPadOS 26.5 update wave

Apple shipped version 26.5 updates for iOS, iPadOS, macOS, watchOS, tvOS, visionOS, and HomePod software, bundling multiple security fixes documented in its advisories. The releases also introduced beta support for end-to-end encrypted RCS messaging on a limited set of carriers, with broader rollout planned over time.

iOS, macOS, and iPadOS 26.5 updates arrive with encrypted RCS messaging and more - Ars Technica

Apple publishes macOS Tahoe 26.4 security advisory

Apple published the security-content advisory for macOS Tahoe 26.4. This represents a distinct macOS security advisory not yet captured in the timeline, separate from the broader March 26, 2026 26.4 release wave and the May 11, 2026 26.5 update entries.

About the security content of macOS Tahoe 26.4 - Apple Support
Mar 26, 20263mo ago

Apple releases broad security update wave fixing 85+ vulnerabilities

Apple released iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, watchOS 26.4, tvOS 26.4, visionOS 26.4, Safari 26.4, and Xcode 26.4, fixing more than 85 vulnerabilities across its product line. The reported issues included AirPlay, kernel, privacy, Keychain, WebKit, and legacy-device flaws, with no listed CVEs reported as exploited in the wild.

Mar 24, 20263mo ago

Apple publishes watchOS 26.3 security update

Apple released watchOS 26.3 and published its security-content advisory. This was a distinct Apple Watch security update issued on the same day as several other March 24, 2026 Apple advisories, ahead of the broader 26.4 release wave two days later.

About the security content of watchOS 26.3 - Apple Support

Apple publishes visionOS 26.3 security update

Apple released visionOS 26.3 and published its security-content advisory. This was a distinct Vision Pro security update issued on the same day as other March 24, 2026 Apple releases, two days before the broader 26.4 update wave.

About the security content of visionOS 26.3 - Apple Support

Apple publishes macOS Sequoia 15.7.4 security update

Apple released macOS Sequoia 15.7.4 and published the corresponding security-content advisory. This was a separate macOS security update issued on the same day as other March 24, 2026 Apple releases, ahead of the broader 26.4 update wave two days later.

About the security content of macOS Sequoia 15.7.4 - Apple Support

Apple publishes macOS Tahoe 26.3 security update

Apple released macOS Tahoe 26.3 and published its security-content advisory. This was a distinct macOS security update issued two days before Apple’s broader 26.4 release wave.

About the security content of macOS Tahoe 26.3 - Apple Support

Apple publishes macOS Sonoma 14.8.4 security update

Apple released macOS Sonoma 14.8.4 and published its security-content advisory. This was a distinct macOS security update issued two days before Apple’s broader 26.4 release wave.

About the security content of macOS Sonoma 14.8.4 - Apple Support (CA)

Apple publishes tvOS 26.3 security update

Apple released tvOS 26.3 and published its security-content advisory. This was a distinct security update for Apple TV issued on the same day as the iOS/iPadOS 18.7.5 release, ahead of the broader 26.4 update wave two days later.

About the security content of tvOS 26.3 - Apple Support (CA)

Apple publishes iOS 26.3 and iPadOS 26.3 security update

Apple released iOS 26.3 and iPadOS 26.3 and published the corresponding security-content advisory. This was a distinct security update for Apple’s current mobile platform branch issued on the same day as several other March 24, 2026 Apple advisories, ahead of the broader 26.4 release wave two days later.

About the security content of iOS 26.3 and iPadOS 26.3 - Apple Support

Apple publishes iOS 18.7.5 and iPadOS 18.7.5 security update

Apple released iOS 18.7.5 and iPadOS 18.7.5 and published the corresponding security-content advisory. The update represents a distinct security release for the 18.x branch ahead of the broader 26.4 update wave later that week.

About the security content of iOS 18.7.5 and iPadOS 18.7.5 - Apple Support
Mar 11, 20264mo ago

Apple publishes iOS 15.8.7 and iPadOS 15.8.7 security update

Apple released iOS 15.8.7 and iPadOS 15.8.7 and published the corresponding security-content advisory. This was a distinct security update for the 15.x branch issued alongside other Apple advisories on March 11, 2026.

About the security content of iOS 15.8.7 and iPadOS 15.8.7 - Apple Support

Apple publishes macOS Sonoma 14.2 security advisory

Apple published the security-content advisory for macOS Sonoma 14.2. This represents a distinct macOS security update issued on the same day as other March 11, 2026 Apple advisories and before the March 24 and March 26 release waves.

About the security content of macOS Sonoma 14.2 - Apple Support

Apple publishes iOS 16.7.15 and iPadOS 16.7.15 security update

Apple released iOS 16.7.15 and iPadOS 16.7.15 and published the corresponding security-content advisory. This was a distinct security update for the 16.x branch issued between the February 2026 update cycle and the later March 24 and March 26 release waves.

About the security content of iOS 16.7.15 and iPadOS 16.7.15 - Apple Support

Apple publishes Safari 17.2 security advisory

Apple published the security-content advisory for Safari 17.2. This represents a distinct Safari security update not already captured in the timeline between the February 2026 Safari 26.3 release and the later May 2026 Safari 26.5 update.

About the security content of Safari 17.2 - Apple Support
Feb 11, 20264mo ago

Apple publishes Safari 26.3 security update

Apple released Safari 26.3 and published its security-content advisory. The update represents a distinct Safari security release preceding the broader 26.4 update wave later in March 2026.

About the security content of Safari 26.3 - Apple Support

Apple publishes tvOS 26.2 security update

Apple released tvOS 26.2 and published its security-content advisory. This was a distinct Apple TV security update issued before the later tvOS 26.3 and broader 26.4 release wave.

About the security content of tvOS 26.2 - Apple Support

Apple publishes watchOS 26.2 security update

Apple released watchOS 26.2 and published its security-content advisory. This was a distinct Apple Watch security update issued alongside other February 11, 2026 platform advisories before the broader March 2026 26.4 release wave.

About the security content of watchOS 26.2 - Apple Support (CA)

Apple publishes visionOS 26.2 security update

Apple released visionOS 26.2 and published its security-content advisory. This was a distinct security update for Vision Pro preceding Apple’s broader March 2026 26.4 update wave.

About the security content of visionOS 26.2 - Apple Support
Feb 3, 20265mo ago

Apple publishes macOS Tahoe 26 security advisory

Apple published the security-content advisory for macOS Tahoe 26. This was a distinct macOS security release preceding the later February, March, and May 2026 Apple update waves already captured in the timeline.

About the security content of macOS Tahoe 26 - Apple Support (CA)
Jan 9, 20266mo ago

Apple publishes Safari 26.2 security advisory

Apple published the security-content advisory for Safari 26.2. This was a distinct Safari security update issued before the later Safari 26.3 and Safari 17.2 advisories already captured in the timeline.

About the security content of Safari 26.2 - Apple Support

Apple credits Google Big Sleep for two WebKit flaws in iOS/iPadOS 26.2

Apple’s security advisory for iOS 26.2 and iPadOS 26.2 listed two WebKit vulnerabilities credited to Google Big Sleep: CVE-2025-43535, which could cause a crafted webpage to crash a process, and CVE-2025-46299, which could disclose internal application states. The advisory entry for CVE-2025-46299 was added on 2026-01-09, showing continued upstream recognition of Big Sleep in Apple security fixes.

Apple WebKit 26.2 follow-up issues credited to Google Big Sleep - Bugflation
Nov 12, 20258mo ago

Apple publishes macOS Ventura 13.5 security advisory

Apple published the security-content advisory for macOS Ventura 13.5. This represents a distinct macOS security update not already captured in the timeline, preceding the January 2026 Apple advisory entries.

About the security content of macOS Ventura 13.5 - Apple Support
May 16, 20251y ago

Apple publishes macOS Sonoma 14.5 security advisory

Apple published the security-content advisory for macOS Sonoma 14.5. This represents a distinct macOS security update not already captured in the timeline, preceding the later Ventura and Sonoma advisory entries already listed.

About the security content of macOS Sonoma 14.5 - Apple Support
May 13, 20242y ago

STAR Labs publishes technical advisory for CVE-2024-27828

STAR Labs disclosed technical details for CVE-2024-27828, explaining that repeated calls to IOSurfaceRootUserClient::s_create_shared_event could cause a reference count leak leading to kernel panic or kernel-level code execution. The advisory credited Pan Zhenpeng with discovering the flaw.

Apple fixes CVE-2024-27828 in multiple operating systems

Apple addressed CVE-2024-27828, a high-severity IOSurfaceRoot memory handling flaw, in iOS/iPadOS 17.5, tvOS 17.5, watchOS 10.5, and visionOS 1.2. The vulnerability could allow a local app to trigger a kernel panic or execute arbitrary code with kernel privileges.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

143 LINKEDOpen in app
Vulnerabilities
103 linked
Out-of-bounds write in Apple KernelUse-after-free in WebKit leading to Safari crashApple Kernel race condition leading to unexpected system terminationDenial-of-Service in Apple Spotlight via unauthorized actionsBuffer Overflow in Apple ImageIO Image ProcessingWebKit Content Security Policy enforcement bypassKernel buffer overflow in Apple operating systemsSafari/WebKit crash on malicious web contentIOHIDFamily memory corruption leading to app terminationMemory corruption in AppleJPEG media file processingWebKit process crash on malicious web contentUse-after-free in Apple IOKitKernel memory layout disclosure in Apple IOHIDFamily loggingUse-after-free in WebKit leading to Safari crashInteger Overflow in Apple Kernel Leading to System TerminationSensitive kernel state leak in Apple Kernel loggingPrivacy preferences bypass in Apple AccountsWebKit Content Security Policy enforcement bypass in Apple Safari and Apple platformsProcess memory corruption in Apple ImageIO image parsingOut-of-bounds write in Apple mDNSResponderWebKit process crash on malicious web content in Apple Safari and Apple platformsOut-of-bounds read in Apple CoreSymbolication file parsingOut-of-bounds read in Apple AccelerateBuffer Overflow in APFS Causing System TerminationSandbox escape in Apple App IntentsUse-after-free in Apple mDNSResponderProcess termination in Apple Audio media file parsingSensitive user data access race condition in Apple StorageImageIO crafted file bounds-check issue causing app terminationWebKit process crash on malicious web contentWebKit use-after-free process crash in Apple Safari and Apple platformsType confusion denial-of-service in Apple LaunchServicesSensitive data leak via malicious website in Apple zlibBuffer Overflow in Apple SceneKitKernel memory disclosure in Apple KernelUse-after-free denial of service in Apple Wi‑Fi packet handlingOut-of-bounds read in Apple IOSurfaceAcceleratorUse-after-free in WebKit web content processingMemory corruption in libjxl decoder grayscale color transformation with LCMS2Sandbox escape in macOS InstallerRoot privilege escalation in Apple StorageKitCoreServices crafted file denial of service in Apple platformsWebKit iframe download settings confusion in SafariPath handling information disclosure in Apple TV App on macOSDenial-of-service in Apple mDNSResponderProtected file system modification in macOS KernelWebKit process crash on malicious web content in Apple Safari and Apple platformsProcess memory corruption in Apple SceneKit image processingOut-of-bounds write in Apple Quick Look file parsingRoot privilege escalation in Apple Kernel authorization handlingContacts privacy bypass in macOS Sync ServicesWebKit process crash on malicious web content in Apple Safari/WebKitUse-after-free RCE in Apple Safari WebCore Style ResolverGatekeeper quarantine bypass via crafted disk image in Apple KernelProtected user data access issue in macOS Tahoe SandboxRemote image display in Apple Mail Drafts Lockdown ModeGatekeeper bypass via crafted ZIP archive in macOS TahoeBuffer Overflow in macOS HFSRoot privilege escalation in macOS UserAccountUpdaterSensitive Information Disclosure in Apple WebKitHeap-based Buffer Overflow RCE in Apple Safari Regular Expression Duplicate Named GroupsOut-of-bounds write in Apple Wi‑Fi allowing kernel code executionSandbox escape in Apple GPU Drivers loggingSensitive data access in Apple Shortcuts due to insufficient user consent promptingRoot privilege escalation in CUPS directory path parsing on macOSWebKit process crash in Apple Safari and Apple platformsSensitive user data access in WebKitProtected user data access issue in macOS Tahoe SpotlightNull pointer dereference DoS in Apple mDNSResponderOut-of-bounds write in Apple kernel components / process crash in WebRTCOut-of-bounds read information disclosure in Apple Model I/O USD libraryRemote DoS buffer overflow in macOS SMBCoreMedia private information access in macOSIP address tracking issue in Apple NetworkingOut-of-bounds write in Apple Model I/O/USD image parsingLock Screen Sensitive Information Disclosure in macOS Tahoe Network ExtensionsApple IOSurfaceRoot reference count leak leading to kernel code executionWebKit malicious web content process crashInformation disclosure in WebKit due to memory initialization issueOut-of-bounds write in Apple Model I/O USD file parsingApple Live Captions lock screen information disclosureSensitive User Data Access in Apple Sandbox ProfilesCoreMedia memory disclosure and denial-of-service via crafted fileKernel memory disclosure in Apple Kernel loggingInstalled App Enumeration in Apple libxpcSensitive user data access in Apple Accounts authorization handlingDenial-of-service in Apple CoreUtils via null pointer dereference802.1X authentication flaw allowing network traffic interceptionSandbox escape in Apple Printing via path handlingDenial-of-service in Apple Calling FrameworkInformation disclosure in Apple GeoServicesInstalled App Enumeration in Apple Crash ReporterApp Privacy Report Logging Bypass in Apple PrivacyUse-after-free in WebKit leading to Safari crashWebKit process crash on malicious web content in Apple Safari and Apple platformsSensitive Data Access via Inconsistent UI State in Apple CoreAnimationDenial-of-Service in Apple Calendar via Resource ExhaustionSensitive Data Exposure in Visual Intelligence During iPhone MirroringLock Screen Restricted Content Exposure in Apple WidgetKitScreen Capture Logic Flaw in Apple Status BarSensitive user data access race condition in Apple FileProviderRoot Privilege Escalation in Apple PackageKitSandbox escape in Apple Icons
Affected products
15 linked
SafariIpadosIosMacos TahoeWatchosTvosVisionosMacos SequoiaMailIphoneMacos SonomaItunesImessageWebkitMacos
Organizations
25 linked
AppleGoogleAnthropiciVerifySTAR Labs SG Pte. LtdDBAppSecurityReverse SocietyCantinaXint CodeBeryllium SecurityHexensTalence SecurityKakao GamesPalo Alto NetworksAISLENosebeard LabsCalif.ioIruMenlo SecurityTrend MicroTrendAI Zero Day InitiativeCalifSupernetworksSafranXint
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Apple Fixes Broad Set of iOS, macOS, and visionOS Vulnerabilities | Mallory