Home / mailingsPDF  

APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10

Posted on 18 August 2026
Apple Security-announce

APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10

iOS 18.7.10 and iPadOS 18.7.10 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/148287.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accessibility
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker with physical access may be able to access sensitive
user data during iPhone Mirroring
Description: This issue was addressed through improved state management.
CVE-2026-64732: Jorge Welch (@jorgwelch)

AirDrop
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker in a privileged network position may be able to
cause a denial-of-service
Description: A reachable assertion was addressed with improved input
validation.
CVE-2026-43667: Arash Ale Ebrahim from SCy-Phy research group of CISPA
Helmholtz Center for Information Security

APFS
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote user may be able to cause unexpected system termination
or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64695: Narendra Singh (@_3P1C), Peter Malone

App Store
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-43801: Rahul Raj

AppleDouble
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-43776: Peter Malone, Nicolas Rabrenovic, Irvin Wang

Audio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/)

AVEVideoEncoder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to execute arbitrary code with kernel
privileges
Description: A buffer overflow was addressed with improved size
validation.
CVE-2026-64747: Franco Belman at Blackwing Intelligence

AVEVideoEncoder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-64762: Franco Belman at Blackwing Intelligence, Dun

BackgroundAssets
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to delete files for which it does not have
permission
Description: A permissions issue was addressed with improved validation.
CVE-2026-64707: YingQi Shi (@Mas0nShi) of DBAppSecurity's WeBin lab

Books
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to modify protected parts of the file system
Description: A race condition was addressed with improved checks.
CVE-2026-43811: Rodolphe Brunetti (@eisw0lf) of Lupus Nova

Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to add contacts without user authorization
Description: An authorization issue was addressed with improved
validation.
CVE-2026-64746: Rodolphe Brunetti (@eisw0lf) of Lupus Nova, Daniel
Febrero

Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted contact may leak sensitive data
Description: The issue was addressed with improved checks.
CVE-2026-64734: Daniel Williams

Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access information about a user's contacts
Description: This issue was addressed with improved checks.
CVE-2026-43797: Arni Hardarson (Neonix Security)

CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted audio file may corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43673: Anonymous working with TrendAI Zero Day Initiative

CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing an audio stream in a maliciously crafted media file
may terminate the process
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43744: ret2happy, Mathis Mansi=C3=A8re, an anonymous researcher

CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected system
termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43803: Rahul Raj

CoreMedia
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted video file may lead to
unexpected app termination
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-43711: James Duffy (@0x4A616D657344)

CoreUI
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted asset catalog may result in
disclosure of process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43738: Peter Malone

CoreVideo
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-43802: an anonymous researcher

curl
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Authentication credentials may be sent to a server on another
origin
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-3784
CVE-2026-3783

Foundation
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to access protected user data
Description: The issue was addressed with improved input sanitization.
CVE-2026-43714: an anonymous researcher

FrontBoard
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed by using HTTPS when sending
information over the network.
CVE-2026-64742: Hu=E1=BB=B3nh T=E1=BA=A5n Ng=C3=A0n

Game Center
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: A parsing issue in the handling of directory paths was
addressed with improved path validation.
CVE-2026-64740: Manuel Fernandez (Stackhopper Security)

Game Center
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to read a persistent device identifier
Description: This issue was addressed with improved data protection.
CVE-2026-43796: Stanislav Jelezoglo, Ilya Andr (andrd3v) of Positive
Technologies

Heimdal
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-64692: Redon Gashi

ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64716: Peter Malone, Jonathan Alush-Aben, Arni Hardarson
CVE-2026-28990: Jiri Ha, Arni Hardarson

ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process
memory
Description: A buffer overflow issue was addressed with improved memory
handling.
CVE-2026-43661: Gandalf4a of PKU-ICODE, Anton Pakhunov, an anonymous
researcher

ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may lead to arbitrary
code execution
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-43818: an anonymous researcher

ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may lead to a
denial-of-service
Description: A type confusion issue was addressed with improved checks.
CVE-2026-64693: Geonha Lee (@leegn4a)

IOSkywalkFamily
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2026-39877: Richard Zana, Dhiyanesh Selvaraj (@redroot97)

IOSurfaceAccelerator
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional
validation.
CVE-2026-64760: Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing
Intelligence, an anonymous researcher

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64749: hxr1, Hiroki Imai (LAC Co., Ltd.), Billy Jheng Bing
Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ashish
Kunwar

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: An information leakage was addressed with additional
validation.
CVE-2026-64744: Ryan Hileman via Xint Code (xint.io)

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-43778: Ashish Kunwar, f0r of MurphySec, Mahmoud Abdelmoniem,
Feng Xue and XGPT of ThreatBook, Wang Yu, Nicolas Rabrenovic, Lyutoon,
Hiroki Imai (LAC Co., Ltd.), F=C3=A1bio Lu=C3=ADs @scanpt, DARKNAVY
(@DarkNavyOrg), an anonymous researcher

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to bypass network filters
Description: An inconsistent user interface issue was addressed with
improved state management.
CVE-2026-64735: Gor Aleksanyan

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-43822: Michal Kosiorek, Eddy Tsalolikhin
CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-64700: Asjid Kalam (@odinshell)

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or
write kernel memory
Description: The issue was addressed with improved input sanitization.
CVE-2026-43724: impost0r (ret2plt), Hyunwoo Kim (@v4bel)

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: The issue was addressed with improved input sanitization.
CVE-2026-43722: Hyunwoo Kim (@v4bel), Feng Xue and XGPT of ThreatBook

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed through improved state management.
CVE-2026-64721: Lukas Gerlach

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds
checking.
CVE-2026-43809: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.
CVE-2026-43757: Wang Yu, Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: This issue was addressed with improved redaction of
sensitive information.
CVE-2026-43754: Ernesto Mart=C3=ADnez Garc=C3=ADa, Calif Research

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
CVE-2026-64723: Ji'an Zhou, Mingxuan Yang, Ye Zhang

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or
corrupt kernel memory
Description: This issue was addressed with improved input validation.
CVE-2026-39868: Ye Zhang (@VAR10CK) of Baidu Security, Vladislav
Shevchenko (Positive Technologies), Billy Jheng Bing Jhong and Pan
Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote user may be able to cause unexpected system termination
or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927)
of STAR Labs SG Pte. Ltd.

Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd.

libarchive
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may result in disclosure
of process memory
Description: This is a vulnerability in open source code and Apple
Software is among the affected projects. The CVE-ID was assigned by a
third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-4424

libc
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-28973: an anonymous researcher

Libnotify
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker may be able to cause unexpected app termination
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun

Managed Configuration
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-64743: Daniel Febrero

Maps
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional
restrictions.
CVE-2026-64738: Robert Mindo, Nathaniel Oh (@calysteon)

mDNSResponder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker on the local network may be able to cause a
denial-of-service
Description: The issue was addressed with improved memory handling.
CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research)

MediaRemote
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved
validation.
CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of
Nosebeard Labs

MobileAccessoryUpdater
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious accessory may be able to cause unexpected app
termination
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-43807: Tristan Madani (@TristanInSec) from Talence Security

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43733: Michael DePlante (@izobashi) of TrendAI Zero Day
Initiative
CVE-2026-43729: Michael DePlante (@izobashi) of TrendAI Zero Day
Initiative

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application
termination or heap corruption
Description: An out-of-bounds write issue was addressed with improved
input validation.
CVE-2026-64772: wh0am1i, stratan (@5tratan)

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application
termination or heap corruption
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-64774: stratan (@5tratan)

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application
termination or heap corruption
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64770: stratan (@5tratan)
CVE-2026-64769: stratan (@5tratan)

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a 3D model may result in disclosure of process memory
Description: A buffer overflow issue was addressed with improved memory
handling.
CVE-2026-64722: wh0am1i

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may cause an unexpected app termination
Description: An out-of-bounds read issue was addressed with improved
input validation.
CVE-2026-64768: stratan (@5tratan)

Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application
termination or heap corruption
Description: A buffer overflow was addressed with improved bounds
checking.
CVE-2026-64771: wh0am1i

Pro Res
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory
management.
CVE-2026-43812: Francisco Knabe

SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2026-64764: stratan (@5tratan)

SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed by removing the
vulnerable code.
CVE-2026-64763: stratan (@5tratan)

SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app
termination or arbitrary code execution
Description: An integer overflow was addressed with improved input
validation.
CVE-2026-64766: stratan (@5tratan)
CVE-2026-64765: stratan (@5tratan)

Siri
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An information disclosure issue was addressed by removing
the vulnerable code.
CVE-2026-43800: Stanislav Jelezoglo

Storage
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with additional validation.
CVE-2026-28996: Alex Radocea

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 307669
CVE-2026-43658: Do Young Park
WebKit Bugzilla: 318348
CVE-2026-65338: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 313452
CVE-2026-43795: wwwlk
WebKit Bugzilla: 311883
CVE-2026-28984: Artem Dinaburg of Trail of Bits via Anthropic CVD

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
WebKit Bugzilla: 311228
CVE-2026-28958: Cantina

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 310234
CVE-2026-28947: dr3dd
WebKit Bugzilla: 313691
CVE-2026-43727: Tommy DeVoss from Braze Security Team (@thedawgyg),
Gurpreet Shergill, Gia Bui (@yabeow) from Calif.io

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 313357
CVE-2026-43735: Rhyru9, Merrick Hare, Kwak Kiyong, Song Nuri, Khai Tran,
John Lussier, Gurpreet Shergill, Drinor Selmanaj (Sentry)

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 313528
CVE-2026-39872: Utkarsh Pal, Ignacio Sanmillan (@ulexec)
WebKit Bugzilla: 312781
CVE-2026-43663: Using GLM =46rom Z.AI, Tristan Madani (@TristanInSec) =from
Talence Security, stratan (@5tratan) of Almamater Technologies, Soyeon
Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit
(@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Brian
Carpenter

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption issue was addressed with improved state
management.
WebKit Bugzilla: 316791
CVE-2026-65334: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 315082
CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 317632
CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security -
Amy Burnett
WebKit Bugzilla: 317231
CVE-2026-43676: Tommy DeVoss from Braze Security Team (@thedawgyg),
Mateusz Krzywicki (iVerify.io), dr3dd

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 317611
CVE-2026-65331: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 316723
CVE-2026-65335: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317450
CVE-2026-65332: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317603
CVE-2026-65333: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317142
CVE-2026-65337: OpenAI Codex Security - Amy Burnett
WebKit Bugzilla: 317349
CVE-2026-65336: Josef Korbel
WebKit Bugzilla: 316996
CVE-2026-65340: Josef Korbel (Citadelo), Claudio Bozzato and Francesco
Benvenuto of Cisco Talos

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 321484
CVE-2026-64781: Thomas Guillem

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption vulnerability was addressed with
improved locking.
WebKit Bugzilla: 321480
CVE-2026-64782: Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
WebKit Bugzilla: 313693
CVE-2026-43734: Jonathan Alush-Aben
WebKit Bugzilla: 313857
CVE-2026-43726: Utkarsh Pal, Tristan Madani (@TristanInSec) from Talence
Security, stratan (@5tratan) of Almamater Technologies, Narendra Singh
(@_3P1C), Josef Korbel (Citadelo), Gia Bui (@yabeow) from Calif.io
WebKit Bugzilla: 317227
CVE-2026-43699: Tommy DeVoss from Braze Security Team (@thedawgyg)
WebKit Bugzilla: 315161
CVE-2026-43742: =D0=AE=D0=BB=D0=B8=D1=8F =D0=9C=D0=B5=D1=80=D1=86=D0=B0=D0==BB=D0=BE=D0=B2=D0=B0

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 316918
CVE-2026-64780: OpenAI Codex Security - Amy Burnett

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A memory corruption issue was addressed with improved
memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 312832
CVE-2026-43725: Luke Francis

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 314115
CVE-2026-43731: dr3dd

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory
corruption
Description: A type confusion issue was addressed with improved checks.
WebKit Bugzilla: 314528
CVE-2026-43705: dr3dd

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 315306
CVE-2026-43708: Behzad Najjarpour Jabbari (@_G4ru_)

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A cross-origin issue was addressed with improved tracking
of security origins.
WebKit Bugzilla: 315368
CVE-2026-43700: Vitaly Simonovich, Muhamad Syaiful, Christian Meurer
Xavier

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may be able to process restricted web
content outside the sandbox
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315004
CVE-2026-43701: Aaron Grattafiori - NVIDIA AI Red Team

WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds write issue was addressed with improved
input validation.
WebKit Bugzilla: 315365
CVE-2026-43745: OpenAI Codex Security - Amy Burnett, Khai Tran

WebKit Canvas
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313175
CVE-2026-43720: Josef Korbel, Gia Bui (@yabeow) from Calif.io

WebKit History
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315528
CVE-2026-64778: Mohit Negi

WebKit Process Model
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to read files outside of its sandbox
Description: An access issue was addressed with improved access
restrictions.
WebKit Bugzilla: 314867
CVE-2026-43821: Brian Carpenter

WebKit Storage
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A memory corruption vulnerability was addressed with
improved locking.
WebKit Bugzilla: 321485
CVE-2026-64779: Tommy DeVoss from Braze Security Team (@thedawgyg),
Shubham Chaskar

WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory
management.
WebKit Bugzilla: 313351
CVE-2026-43717: Nan Wang (@eternalsakura13)

WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 317324
CVE-2026-28979

WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an
unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved
bounds checking.
WebKit Bugzilla: 319404
CVE-2026-64719: Shaheen Fazim

Wi-Fi
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker in physical proximity may be able to corrupt process
memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64726: Peter Malone, Mathis Mansi=C3=A8re

WorkoutKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state
management.
CVE-2026-64755: Stuart Wallace

Additional recognition

CoreMedia
We would like to acknowledge yaohway for their assistance.

Kernel
We would like to acknowledge Billy Jheng Bing Jhong and Pan Zhenpeng
(@Peterpan0927) of STAR Labs SG Pte. Ltd., Chris Betz, James Duffy (
@0x4A616D657344 ), Mathis Mansi=C3=A8re, Tristan Rousseau, Yeojin Kim,
YingMuo (@YingMuo) of DEVCORE Research Team for their assistance.

mDNSResponder
We would like to acknowledge Cem Onat Karagun, He Wei (=E3=82=AE=E3=82=AB=E3==82=AF), Jex Amro,
=E7=AB=A0=E9=B1=BC=E5=93=A5 (@aipy) of aipyaipy.com for their =assistance.

Printing UIKit
We would like to acknowledge Jacolon Walker ( @call_eax ) for their
assistance.

WebKit
We would like to acknowledge Henock Habte, Souta Sugiyama for their
assistance.

WebKit JavaScript Bindings
We would like to acknowledge Karan Kurani for their assistance.

This update is available through iTunes and Software Update on your iOS
device, and will not appear in your computer's Software Update
application, or in the Apple Downloads site. Make sure you have an
Internet connection and have installed the latest version of iTunes from
https://www.apple.com/itunes/

iTunes and Software Update on the device will automatically check
Apple's update server on its weekly schedule. When an update is
detected, it is downloaded and the option to be installed is presented
to the user when the iOS device is docked. We recommend applying the
update immediately if possible. Selecting Don't Install will present the
option the next time you connect your iOS device.

The automatic update process may take up to a week depending on the day
that iTunes or the device checks for updates. You may manually obtain
the update via the Check for Updates button within iTunes, or the
Software Update on your device.

To check that the iPhone, iPod touch, or iPad has been updated:

* Navigate to Settings * Select General * Select About. The version
after applying this update will be "iOS 18.7.10 and iPadOS 18.7.10".

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

 

TOP