Apple Patches Dozens of OS Vulnerabilities
Apple released updates fixing dozens of vulnerabilities across iOS, iPadOS, macOS, tvOS, watchOS and visionOS, several allowing kernel-level arbitrary code execution.
MS-ISAC issued an advisory covering a large batch of vulnerabilities patched across Apple's full product line, including iOS/iPadOS 26.5, macOS Tahoe 26.5, Sequoia 15.7.7, Sonoma 14.8.7, tvOS, watchOS, and visionOS 26.5. The most severe issues could allow an app or remote attacker to execute arbitrary code with kernel privileges, gain root, corrupt kernel memory, or bypass Gatekeeper protections via crafted disk images or ZIP archives. Many of the remaining flaws involve memory corruption from processing maliciously crafted images, media, or web content, sandbox escapes, denial-of-service conditions, and various privacy/data-disclosure issues (e.g., unauthorized Contacts access, screen capture, sensitive data leaks via web content or physical device access).
MS-ISAC reports no evidence of in-the-wild exploitation at this time, and the primary attack vector highlighted is drive-by compromise (a user interacting with malicious content, apps, or websites) rather than active targeting. Given the scale of impacted products and the presence of multiple kernel-level and remote code execution bugs, organizations and end users should prioritize timely patching, particularly for devices with elevated privileges, while applying standard hardening measures such as least-privilege configurations, exploit protection, and DNS/URL filtering to reduce exposure until updates are deployed.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2026-047
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free