iOS Security News

Security news specific to Apple iOS: vulnerabilities, exploitation and patches affecting iPhone and iPad.

iOS's tightly controlled app ecosystem shifts the threat model toward platform-level and zero-click vulnerabilities, some of which have shown up in targeted-surveillance campaigns. iOS-specific CVEs, in-the-wild exploitation and Apple's security update releases land here. Apple controls patch delivery centrally, so fixes here tend to reach the install base faster than on more fragmented platforms.

Recent iOS items

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks 🖋️ Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may ha…
@cibsecurity · Sep 28, 2026
CVE-2026-86950 An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a mal…
@cveNotify · Sep 28, 2026
Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks. CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are…
@thehackernews · Sep 28, 2026
CVE-2026-101047 Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL toke…
@cveNotify · Sep 27, 2026
CVE-2026-100581 OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device bac…
@cveNotify · Sep 26, 2026
CVE-2025-43418 This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical acce…
@cveNotify · Sep 26, 2026
CVE-2025-43507 A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An…
@cveNotify · Sep 26, 2026
CVE-2025-43503 An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Taho…
@cveNotify · Sep 26, 2026
CVE-2025-43499 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may…
@cveNotify · Sep 26, 2026
CVE-2025-43493 The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a mal…
@cveNotify · Sep 26, 2026
CVE-2025-43460 A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user…
@cveNotify · Sep 26, 2026
CVE-2025-43458 This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visi…
@cveNotify · Sep 26, 2026
CVE-2025-43454 This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock. 🎖
@cveNotify · Sep 26, 2026
CVE-2025-43450 A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the curren…
@cveNotify · Sep 26, 2026
CVE-2025-43444 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1…
@cveNotify · Sep 26, 2026
CVE-2025-43443 This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, wa…
@cveNotify · Sep 26, 2026
CVE-2025-43448 This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,…
@cveNotify · Sep 26, 2026
CVE-2025-43445 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.…
@cveNotify · Sep 26, 2026
CVE-2025-43442 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what other…
@cveNotify · Sep 26, 2026
CVE-2025-43439 A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to fingerprint…
@cveNotify · Sep 26, 2026
CVE-2025-43438 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visio…
@cveNotify · Sep 26, 2026
CVE-2025-43434 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visio…
@cveNotify · Sep 26, 2026
CVE-2025-43429 A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, v…
@cveNotify · Sep 26, 2026
CVE-2025-43426 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data. 🎖
@cveNotify · Sep 26, 2026
CVE-2025-43423 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, vision…
@cveNotify · Sep 26, 2026
CVE-2025-43399 This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be abl…
@cveNotify · Sep 26, 2026
CVE-2025-43389 A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,…
@cveNotify · Sep 26, 2026
CVE-2025-43386 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, vi…
@cveNotify · Sep 26, 2026
CVE-2025-43385 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tah…
@cveNotify · Sep 26, 2026
CVE-2025-43384 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tah…
@cveNotify · Sep 26, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.