CERT-In Advisory
CIAD-2026-0041
Multiple Vulnerabilities in Apple Products
Original Issue Date: August 19, 2026
Severity Rating: Critical
Software Affected
- Apple iOS versions prior to 26.6.1
- Apple iPadOS versions prior to 26.6.1
- Apple iOS versions prior to 18.7.10
- Apple iPadOS versions prior to 18.7.10
- Apple macOS Tahoe versions prior to 26.6.2
Overview
Multiple vulnerabilities have been reported in Apple products which could allow an attacker to execute arbitrary code on the targeted system.
Target Audience: All end-user organizations and individuals using the Apple iOS, ipadOS and macOS devices.
Risk Assessment: Very High risk of extremely sophisticated attack or arbitrary code execution.
Impact Assessment: Potential for sophisticated targeted attacks.
Description
Multiple vulnerabilities exist in Apple products due to memory corruption, use-after-free, out-of-bounds read/write, buffer overflow, integer overflow, type confusion, authentication, authorization, permission, and logic issues across various Apple components, including CoreAudio, ImageIO, Kernel, WebKit, IOGPUFamily, AVEVideoEncoder, SceneKit, Model I/O, and other system frameworks.
Successful exploitation of these vulnerabilities could enable targeted attacks, potentially allowing attackers to execute arbitrary code with elevated privileges, access sensitive information, compromise application or system security boundaries, or cause denial-of-service conditions on affected Apple devices.
For complete list of affected products, CVEs, workarounds and solutions, refer to the Apple security updates.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.apple.com/en-us/148282
https://support.apple.com/en-us/148287
https://support.apple.com/en-us/148281
https://support.apple.com/en-us/148286
Vendor Information
Apple
https://www.apple.com/
References
https://support.apple.com/en-us/148282
https://support.apple.com/en-us/148287
https://support.apple.com/en-us/148281
https://support.apple.com/en-us/148286
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|