iOS 18.7.10 and iPadOS 18.7.10
Apple released iOS 18.7.10 and iPadOS 18.7.10 on 2026-08-17. This release fixes security vulnerabilities — see the technical details below.
Manufacturer release date: 2026-08-17
Article last updated: 2026-10-05
Sources last checked: 2026-10-05
What changed
Why it matters
What to do
On the device, open Settings > General > Software Update and install the version Apple offers.
Open Settings > General > Software Update (iPhone/iPad) or System Settings > General > Software Update (Mac) to see the installed version.
Apple: Update the software on your iPhone or iPadUpdates only reach the model generations Apple lists for each release. Older devices stay on an older branch — check Apple's security releases page for which branch the model receives.
Affected devices and versions
Covers: iPhone / iOS, iPad / iPadOS.
Applies to: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation.
We don't know which software your device is running. If your device is running an affected version, updating is the recommended action — check the installed version with the steps above.
Security fixes in this release
This release fixes 28 vulnerabilities — see the technical details below.
Technical details (28 vulnerabilities)
CVE-2026-64714
Impact: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 5.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65331
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64715
Impact: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 6.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-43795
Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65335
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-43667
Impact: A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5.
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to cause a denial-of-service.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 6.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64717
Impact: A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6.
A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6)
Severity: 6.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 6.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-28960
Impact: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 7.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 7.5 (HIGH); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64784
Impact: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-43794
Impact: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 8.8 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 8.8 (HIGH); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64780
Impact: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65333
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65334
Impact: A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65340
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65338
Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65336
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65341
Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 5.4 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 5.4 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-28984
Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65332
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64781
Impact: The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64760
Impact: An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27.
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 5.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65337
Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64779
Impact: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 3.1 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 3.1 (LOW); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64782
Impact: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 3.1 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 3.1 (LOW); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-64778
Impact: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted website may leak sensitive data.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 6.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65355
Impact: An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1.
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.
Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)
Severity: 4.3 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-65404
Impact: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 5.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
CVE-2026-84489
Impact: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.
Affected versions in the official record: iPadOS (versions before 18.7.10)
Severity: 5.5 (CVSS 3.1)
Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Source: Official CVE record (CVE List / NVD)
The full CVE list for this release is above. Individual vulnerability details come from the official CVE record (CVE List / NVD) and the manufacturer's own advisory where published.
Official sources
Record history
- 2026-10-05 — published: Initial automated publication from official sources.
This article is automatically summarised from official sources. It isn't a manual editorial review. Guidance can help reduce risk. No setting or service can guarantee complete online safety.
Spotted something inaccurate in this article?Share feedback