A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.
GPU Drivers. An out-of-bounds write issue was addressed with improved bounds checking.
Messages Composition. The issue was addressed with improved deletion.
Web App. A logic issue was addressed with improved restrictions.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read sensitive location information.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
A flaw was found in WebKitGTK.
Impact: Maliciously crafted web content may violate iframe sandboxing policy. Description: This issue was addressed with improved iframe sandbox enforcement.
Reference: https://webkitgtk.org/security/WSA-2021-0002.html
A flaw was found in WebKitGTK.
Impact: A malicious website may be able to access restricted ports on arbitrary servers. Description: A port redirection issue was addressed with additional port validation.
Reference: https://webkitgtk.org/security/WSA-2021-0002.html
A use after free issue was addressed with improved memory management. https://webkitgtk.org/security/WSA-2022-0004.html#CVE-2022-22624
A use after free issue was addressed with improved memory management. https://webkitgtk.org/security/WSA-2022-0004.html#CVE-2022-22628
A logic issue was addressed with improved state management. https://webkitgtk.org/security/WSA-2022-0004.html#CVE-2022-22637
WebKit. A memory corruption issue was addressed with improved state management.
AMD. A buffer overflow issue was addressed with improved memory handling.
AMD. A buffer overflow issue was addressed with improved memory handling.
AppleMobileFileIntegrity. This issue was addressed with improved checks to prevent unauthorized actions.
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.
A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An attacker may be able to leak user account emails.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to access user-sensitive data.
WebKit. Multiple memory corruption issues were addressed with improved memory handling.