Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisory

Apple Fixes Multiple Kernel, WebKit, and Data Exposure Flaws in iOS, iPadOS, and watchOS

Updated 3mo agoFirst seen Mar 29, 20265 sources

Apple released security updates for iOS 18.7.7, iPadOS 18.7.7, and watchOS 26.4 to address a wide range of vulnerabilities affecting supported iPhones, iPads, and Apple Watch Series 6 and later. The patches cover core components including Kernel, WebKit, Security, CoreMedia, CoreUtils, Audio, 802.1X, and UIFoundation, with Apple warning that successful exploitation could enable network traffic interception, denial of service, unauthorized access to sensitive data, installed-app enumeration, Keychain access, kernel memory disclosure, and in some cases kernel memory write or Activation Lock bypass.

Share:
Apple Fixes Multiple Kernel, WebKit, and Data Exposure Flaws in iOS, iPadOS, and watchOS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 1, 20263mo ago

Apple expands iOS 18.7.7/iPadOS 18.7.7 rollout with DarkSword protections

Apple updated its iOS 18.7.7 and iPadOS 18.7.7 security advisory to say the March 24 release was later expanded to more devices so users with Automatic Updates could receive protections against web attacks called DarkSword. Apple also noted the DarkSword-related fixes had first shipped in 2025.

About the security content of iOS 18.7.7 and iPadOS 18.7.7 - Apple Support
Mar 24, 20263mo ago

Apple releases iOS 26.4 and iPadOS 26.4 security updates

Apple published advisory APPLE-SA-03-24-2026-1 for iOS 26.4 and iPadOS 26.4, fixing numerous vulnerabilities across components including Kernel, WebKit, Baseband, Telephony, Mail, Security, Siri, Printing, and Accounts. The update addressed risks such as denial of service, sandbox escape, kernel memory corruption, privacy leaks, installed-app enumeration, Keychain exposure, and multiple web security boundary bypasses.

Full Disclosure: APPLE-SA-03-24-2026-1 iOS 26.4 and iPadOS 26.4

Apple releases tvOS 26.4 security update

Apple published advisory APPLE-SA-03-24-2026-6 for tvOS 26.4 for Apple TV HD and Apple TV 4K models, addressing multiple vulnerabilities across networking, media, kernel, privacy, sandboxing, and WebKit components. The fixes covered risks including traffic interception, denial of service, app crashes, information disclosure, installed-app enumeration, fingerprinting, kernel memory corruption, and sandbox bypass via malicious web content or crafted files.

Full Disclosure: APPLE-SA-03-24-2026-6 tvOS 26.4

Apple releases watchOS 26.4 security update

Apple published advisory APPLE-SA-03-24-2026-7 for watchOS 26.4 for Apple Watch Series 6 and later, fixing multiple vulnerabilities across components such as 802.1X, Accounts, CoreMedia, Kernel, Security, Siri, and WebKit. The patched issues included risks like network traffic interception, unauthorized data access, denial of service, kernel memory disclosure, Keychain access, app enumeration, fingerprinting, and WebKit sandbox or policy bypasses.

Apple releases iOS 18.7.7 and iPadOS 18.7.7 security updates

Apple published advisory APPLE-SA-03-24-2026-2 for iOS 18.7.7 and iPadOS 18.7.7, addressing numerous vulnerabilities affecting supported older iPhone and iPad models. The fixes covered issues including traffic interception, denial of service, sensitive data exposure, kernel flaws, Activation Lock bypass, Keychain access, and multiple WebKit security bypasses.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

67 LINKEDOpen in app
Vulnerabilities
43 linked
Heap buffer over-read in libpng png_do_quantizecurl OAuth2 Bearer Token Leak on Cross-Protocol RedirectKernel sensitive state disclosure in Apple operating systemsDenial-of-service in Apple CoreUtils via null pointer dereference802.1X authentication flaw allowing network traffic interceptionUse-after-free in Apple KernelWebKit Content Security Policy enforcement bypass via malicious web contentOut-of-bounds access in Apple CoreMedia audio stream processingUse-after-free in Apple Audio web content processingInstalled App Enumeration in Apple Crash ReporterStack Overflow DoS in Apple UIFoundationKernel memory disclosure in Apple Kernel loggingKeychain access permissions flaw in Apple Security FrameworkSame Origin Policy bypass in WebKit Navigation APIWebKit cross-origin script message handler accessSensitive Data Access via Directory Path Parsing in Apple DeviceLinkCross-site scripting in WebKitSensitive Data Access via Symlink Validation Flaw in Apple ClipboardInstalled App Enumeration in Apple iCloudDNS Query Leakage with Private Relay Enabled in Safari/WebKitSensitive data exposure via insufficient log redaction in Apple FocusUse-after-free in AppleKeyStoreUnexpected app termination in Apple Vision file parsingActivation Lock bypass in iTunes Store path handlingInstalled App Enumeration in Apple libxpcWebKit sandbox escape via restricted web content processingKernel memory corruption in Apple operating systemsType confusion in Apple AudioInformation disclosure in Apple GeoServicesUser fingerprinting in Apple Sandbox ProfilesSensitive user data access in Apple Accounts authorization handlingWebKit Sandboxing authorization issue allowing user fingerprintingSensitive information disclosure on locked Apple devices via SiriBuffer Overflow in Apple Baseband on iPhone 16eBuffer Overflow in Apple TelephonyPasscode-based bypass of biometrics-gated Protected Apps in Apple App ProtectionSandbox escape in Apple Printing via path handlingDenial-of-service in Apple Calling FrameworkUnexpected app termination in Apple BasebandPrivacy bypass in Apple Mail remote content protectionsInstalled App Enumeration in Apple iCloudWebKit use-after-free leading to process crashWebKit process crash on maliciously crafted web content
Affected products
10 linked
IosSafariItunesIpadosIcloudShortcutsMusicTvosWatchosMail
Organizations
14 linked
Trend MicroRenaultAppleGoogleAnt GroupNosebeard LabsSupernetworksSafranTikTokFuzzingLabsSecuRingTotally Not Malicious SoftwareVoynich GroupIntretech
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.