PT-2026-53719 · Apple · Macos Tahoe+3
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 26.5.2
iPadOS versions prior to 26.5.2
macOS Tahoe versions prior to 26.5.2
Description
Insufficient input sanitization in Apple platforms allows a locally running app to reach sensitive kernel code paths. This improper input validation can lead to memory corruption, enabling an attacker to cause unexpected system termination or write to kernel memory. Such exploitation may lead to privilege escalation or full device compromise. Real-world incidents indicate that this issue is being chained with WebKit exploits to escalate from browser-based code execution to full system control.
Recommendations
Update iOS to version 26.5.2.
Update iPadOS to version 26.5.2.
Update macOS Tahoe to version 26.5.2.
Fix
DoS
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Macos Tahoe