Apple published security advisories detailing vulnerability fixes across multiple iOS and iPadOS versions, including iOS/iPadOS 16.7, 17.2, 18.1, 18.3, 26.1, and 26.2. The advisories describe a range of impacts such as sandbox escapes (including Web Content sandbox breakout), privacy issues where apps could access or expose sensitive user data via insufficient log redaction, file-system modification via temporary-file handling, and memory-safety flaws (e.g., out-of-bounds reads, type confusion, and bounds-checking issues) that could lead to crashes or memory corruption. Apple attributes fixes to changes like improved protocol handling, cache handling, input validation, and additional permission restrictions, and references issues by CVE where available.
Several advisories also highlight device-state and authentication/logic weaknesses: iOS/iPadOS 18.3 includes a case where an attacker with physical access to an unlocked device could access Photos while the app is locked (CVE-2025-24141), while iOS/iPadOS 18.1 includes a lock-screen exposure issue (CVE-2024-44274) and a Shortcuts-related path-handling flaw that could allow arbitrary shortcut execution without user consent (CVE-2024-44255). The iOS/iPadOS 26.x advisories include privacy and permission issues (e.g., identifying installed apps, screenshots of sensitive embedded views), potential kernel memory corruption/system termination conditions, and logic/UI issues affecting security posture (e.g., passcode requirement timing after Face ID enrollment restore scenarios and potential FaceTime caller ID spoofing), with multiple findings credited to external researchers and teams (including Google Project Zero, ByteDance IES Red Team, and others).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Apple published the iOS 26.1 and iPadOS 26.1 security advisory on January 16, 2026, documenting the vulnerabilities fixed in the November 2025 release and noting some entries had been updated on December 12, 2025.
Apple published the iOS 26.2 and iPadOS 26.2 security advisory on January 9, 2026, describing the December 2025 fixes and noting added or updated entries including a FaceTime caller ID spoofing issue and additional web-content crash vulnerabilities.
Apple released iOS 26.2 and iPadOS 26.2 on December 12, 2025, fixing numerous vulnerabilities including exposure of payment tokens, Safari history and hidden photos, file- and HID-triggered memory corruption, and a web-content flaw that may have been exploited in a highly targeted attack.
On November 11, 2025, Apple published security advisories for iOS 18.4 and iPadOS 18.4 as well as visionOS 2.4, detailing numerous fixes for privacy leaks, privilege escalation, sandbox escapes, local-network attack vectors, web spoofing, and memory-safety flaws.
Apple published the security advisory for iOS 26 and iPadOS 26 on November 4, 2025, later surfaced in the referenced support document, detailing numerous CVE-tracked vulnerabilities fixed in the September 2025 release.
Apple released iOS 26.1 and iPadOS 26.1 on November 3, 2025, addressing a broad set of privacy, permission-bypass, sandbox escape, keystroke monitoring, kernel memory corruption, and malicious web-content issues.
Apple released iOS 26 and iPadOS 26 on September 15, 2025, fixing numerous vulnerabilities including memory corruption, sensitive data exposure, sandbox bypasses, keystroke monitoring without permission, and web-content processing flaws.
On August 20, 2025, Apple released iOS 18.6.2 and iPadOS 18.6.2 to fix CVE-2025-43300, an out-of-bounds write in image processing that could cause memory corruption. Apple said it was aware the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Apple published the macOS Ventura 13.7.5 security update advisory on July 29, 2025, documenting numerous fixes for privilege escalation, sandbox escapes, authentication bypasses, privacy leaks, memory corruption, and network-reachable issues.
Apple added several CVE entries to the macOS Ventura 13.7.5 security advisory on April 28, 2025, with further updates on May 28, 2025 and an additional entry on July 29, 2025.
Apple published the security advisory for iOS 18.2 and iPadOS 18.2 on April 2, 2025, detailing vulnerabilities fixed in the December 2024 release and noting several entries added or updated in early 2025.
Apple published the security content document for iOS 18 and iPadOS 18 on March 3, 2025, summarizing the vulnerabilities addressed in the September 2024 release and subsequent advisory updates.
Apple added or updated multiple CVE entries in the iOS 18 and iPadOS 18 security advisory on October 28, 2024 and again on March 3, 2025, expanding the documented details of vulnerabilities fixed in the September 2024 release.
Apple released iOS 18.2 and iPadOS 18.2 on December 11, 2024, fixing multiple issues including authentication bypasses, sandbox escapes, sensitive data exposure, network privacy weaknesses, and memory-safety flaws.
Apple released iOS 18 and iPadOS 18 on September 16, 2024, addressing numerous vulnerabilities affecting privacy, sandboxing, file handling, Bluetooth, VPN/networking, and web content processing on supported iPhones and iPads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
support.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcecc.zdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.