All security updates
AppleSecurity update availableSecurity updateAutomatically summarised from official sources

iOS 18.7.10 and iPadOS 18.7.10

Apple released iOS 18.7.10 and iPadOS 18.7.10 on 2026-08-17. This release fixes security vulnerabilities — see the technical details below.

Manufacturer release date: 2026-08-17

Article last updated: 2026-10-05

Sources last checked: 2026-10-05

What changed

Apple publishes the fixed vulnerabilities in its security content advisory for this release. Use the official release page below for the current details.

Why it matters

If your device is running an earlier version of the affected software, updating closes the vulnerabilities listed below.

What to do

On the device, open Settings > General > Software Update and install the version Apple offers.

Open Settings > General > Software Update (iPhone/iPad) or System Settings > General > Software Update (Mac) to see the installed version.

Apple: Update the software on your iPhone or iPad

Updates only reach the model generations Apple lists for each release. Older devices stay on an older branch — check Apple's security releases page for which branch the model receives.

Affected devices and versions

Covers: iPhone / iOS, iPad / iPadOS.

Applies to: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation.

We don't know which software your device is running. If your device is running an affected version, updating is the recommended action — check the installed version with the steps above.

Security fixes in this release

This release fixes 28 vulnerabilities — see the technical details below.

Technical details (28 vulnerabilities)

CVE-2026-64714

Impact: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 5.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65331

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64715

Impact: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 6.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-43795

Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65335

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-43667

Impact: A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5.

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to cause a denial-of-service.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 6.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64717

Impact: A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6.

A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6)

Severity: 6.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 6.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-28960

Impact: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 7.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 7.5 (HIGH); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64784

Impact: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-43794

Impact: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 8.8 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 8.8 (HIGH); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64780

Impact: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65333

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65334

Impact: A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65340

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65338

Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65336

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65341

Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 5.4 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 5.4 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-28984

Impact: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65332

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64781

Impact: The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64760

Impact: An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27.

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 5.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65337

Impact: This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64779

Impact: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 3.1 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 3.1 (LOW); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64782

Impact: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27.

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 3.1 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 3.1 (LOW); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-64778

Impact: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27.

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted website may leak sensitive data.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 6.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 6.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65355

Impact: An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1.

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 26.6.1. A website may be able to determine a user's IP address with Private Relay turned on.

Affected versions in the official record: iPadOS (versions before 18.7.10) · iPadOS (versions from 26.0 before 26.6.1)

Severity: 4.3 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 4.3 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-65404

Impact: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application may be able to bypass Privacy preferences.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 5.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

CVE-2026-84489

Impact: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service.

Affected versions in the official record: iPadOS (versions before 18.7.10)

Severity: 5.5 (CVSS 3.1)

Scoring source: CVSS 3.1 base score 5.5 (MEDIUM); source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Source: Official CVE record (CVE List / NVD)

The full CVE list for this release is above. Individual vulnerability details come from the official CVE record (CVE List / NVD) and the manufacturer's own advisory where published.

Official sources

Record history

  • 2026-10-05 — published: Initial automated publication from official sources.

This article is automatically summarised from official sources. It isn't a manual editorial review. Guidance can help reduce risk. No setting or service can guarantee complete online safety.

Spotted something inaccurate in this article?Share feedback