Visualização de leitura

Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS

Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.

The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.

Apple follows a policy of withholding technical details about security flaws until it completes an investigation and security updates are broadly available.

Several flaws affect components that process media, web content, and graphics. Apple fixed an integer overflow in ImageIO that could allow a specially crafted image to trigger arbitrary code execution. A separate ImageIO issue could cause a denial-of-service condition when a vulnerable device processes a malicious image.

Apple Fixes 28 Security Vulnerabilities

The updates also address multiple issues in IOGPUFamily, an Apple graphics framework. Apple warned that malicious web content could cause memory corruption.

At the same time, other flaws could enable remote attackers to terminate a system unexpectedly or allow a local application to read kernel memory. Such bugs are significant because the kernel runs with high privileges and controls core operating-system functions.

An additional kernel-level issue in the older iOS 18.7.10 and iPadOS 18.7.10 releases could allow a malicious application to execute arbitrary code with kernel privileges via a buffer overflow. Apple resolved the flaw through improved size validation.

Apple patched an Audio logic issue that could allow an application to leak sensitive user information. The company addressed the problem by adding improved checks. This vulnerability affects both macOS Tahoe 26.6.2 and the newer iOS and iPadOS releases.

The mobile updates also include an Accessibility fix for devices running iOS 18.7.10 and iPadOS 18.7.10. Apple said an attacker with physical access could potentially access sensitive data during iPhone Mirroring. This feature links an iPhone with a Mac. The issue was fixed through improved state management.

CVEComponentAffected release(s)ImpactVulnerability type / remediation
CVE-2026-65339AudioiOS/iPadOS 26.6.1; macOS Tahoe 26.6.2An app may leak sensitive user informationLogic issue; improved checks
CVE-2026-65347ImageIOiOS/iPadOS; macOSProcessing an image may cause DoSImproved checks
CVE-2026-65346ImageIOiOS/iPadOS; macOSProcessing an image may enable arbitrary code executionInteger overflow; improved input validation
CVE-2026-64788IOGPUFamilyiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-65343KerneliOS/iPadOS; macOSRemote attacker may terminate the systemUse-after-free; improved memory management
CVE-2026-65349KerneliOS/iPadOS; macOSApp may terminate the system or read kernel memoryOut-of-bounds read; improved input validation
CVE-2026-65330KerneliOS/iPadOS; macOSApp may terminate the system or corrupt kernel memoryImproved memory handling
CVE-2026-65329TelephonyiOS 26.6.1 only; iPhone 11 and laterPrivileged network attacker may bypass IPSec authentication and intercept trafficAuthentication issue; improved state management
CVE-2026-64784WebKitiOS/iPadOS; macOSCrafted web content may crash SafariOut-of-bounds access; improved bounds checking
CVE-2026-43795WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65338WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65341WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-64782WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking
CVE-2026-64781WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved input validation
CVE-2026-65351WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65340WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65337WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65336WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65335WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65333WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65332WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65331WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-64715WebKitiOS/iPadOS; macOSCrafted web content may cause an unexpected process crashUse-after-free; improved memory management
CVE-2026-64780WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved checks
CVE-2026-65334WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved state management
CVE-2026-43794WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionMemory-corruption flaw; improved memory handling
CVE-2026-64787WebKitiOS/iPadOS; macOSCrafted web content may terminate a processUse-after-free; improved memory management
CVE-2026-64778WebKit HistoryiOS/iPadOS; macOSVisiting a crafted website may leak sensitive dataImproved checks
CVE-2026-64779WebKit StorageiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking

Apple also corrected an IPSec authentication issue in iOS 26.6.1 and iPadOS 26.6.1. A threat actor in a privileged network position could bypass IPSec authentication and intercept network traffic, posing a risk to users on hostile or compromised networks.

iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

The iOS 18.7.10 and iPadOS 18.7.10 updates protect older iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th-generation devices. Users should install the updates promptly. Apple notes that iPhone, iPad, Apple TV, Apple Watch, and Vision Pro software cannot be downgraded after an update is installed.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS appeared first on Cyber Security News.

Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage

CVE-2026-20685 is a path traversal vulnerability affecting Apple’s Private Cloud Compute (PCC), potentially allowing attackers to write files as root during node boot and redirect sensitive AI inference telemetry to an external server.

Sentry Security researcher Drinor received a $150,000 Apple Security Bounty for discovering and reporting CVE-2026-20685, a flaw that could expose sensitive data and allow unauthorized access.

PCC is Apple’s server-side platform for Apple Intelligence requests that are too complex to run entirely on an iPhone, iPad, or Mac. Apple describes the system as an extension of device-level privacy protections into the cloud.

Its design relies on stateless request processing, cryptographic attestation of approved software, and tightly controlled logging systems.

The flaw was found in darwin-init, the first userspace process launched on a PCC node. Running as PID 1 with root privileges, darwin-init downloads, extracts, personalizes, and installs cryptex packages before triggering a userspace reboot into the normal operating environment.

Apple Private Cloud Compute Vulnerability

According to the Sentry Security research, darwin-init selected an archive extractor by examining only the first 4 bytes of an incoming file. A malicious tar archive did not match known Apple archive signatures and was passed to a generic extraction function.

That function appended archive entry names to the intended output path without properly validating path traversal sequences such as ../../../../.

As a result, a crafted archive could escape its extraction folder and write attacker-controlled files to persistent locations on the PCC node’s writable data volume, including /var/db/.

Because darwin-init runs as root before steady-state security services load, those files could remain available after the userspace reboot.
The researcher built a malicious archive that contained both traversal entries and a structurally valid cryptex bundle.

This was important because an invalid cryptex installation would prevent the system from completing its boot process. By combining a legitimate-looking bundle with malicious file paths, the archive could pass installation checks while placing files outside the intended extraction directory.

One demonstrated impact involved PCC’s internal splunkloggingd service. The service checks for a configuration file on the writable data volume and starts when that file exists.

By using the root file write to create a malicious logging configuration, the researcher redirected PCC telemetry to a controlled endpoint.

The redirected data reportedly included CloudBoard daemon activity, node events, and metadata associated with AI inference requests.

During test inference activity in Apple’s Virtual Research Environment, the logs exposed values such as application bundle identifiers, workload types, request identifiers, device-grouping metadata, token counts, output-token metrics, and latency measurements.

These details could reveal information about how a PCC node processes AI requests. For example, input token counts corresponded to prompt length.

At the same time, other values exposed first-token latency, speculative decoding information, and model-related telemetry. Apple’s source code reportedly identifies some of the affected metadata as information that should not be logged publicly.

The Sentry Security research also found an attestation gap. Apple’s PCC attestation process appeared to confirm that approved software and cryptotex components were installed.

However, it did not measure writable data volume files that could influence daemon behavior at runtime. A modified node could therefore appear identical to a clean node during software attestation checks.

Apple classified CVE-2026-20685 as an information disclosure issue with a CVSS score of 6.5. The company fixed the vulnerability in PCC releases 5E290.3 and later. The testing was conducted solely in Apple’s official Virtual Research Environment, with no production PCC infrastructure involved.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Apple Private Cloud Compute Flaw Enables Root File Writes and AI Inference Telemetry Leakage appeared first on Cyber Security News.

❌