NCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOS
Apple has fixed multiple vulnerabilities in various versions of iOS and iPadOS. Several memory management errors such as use-after-free, buffer overflows, out-of-bounds reads and writes, integer overflows, race conditions, and insufficient input validation have been resolved. These errors can lead to unexpected system or application terminations, memory corruption, privilege escalation, sandbox escape, unauthorized access to sensitive user data, and in some cases arbitrary code execution. Issues with state management, permissions, sandboxing, and UI spoofing in Safari and other Apple components have also been addressed. The vulnerabilities are present in core components of the operating systems and affect a wide range of Apple platforms. Exploitation can occur via specially crafted files, network traffic, web content, or applications. No specific proof-of-concept details are mentioned in the input.
CSIRTS triage
- What
- Multiple vulnerabilities in iOS and iPadOS can lead to memory corruption, privilege escalation, and arbitrary code execution.
- Who is affected
- Users of various versions of iOS and iPadOS are affected.
- Urgency
- Remediation is high urgency due to the potential for exploitation and severe impacts.
- Action
- Update to the latest version of iOS and iPadOS to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch iOS and iPadOS
Get an email when a new iOS and iPadOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0266
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-44240.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Low exploitation riskCVE-2026-289280.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-289310.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-289730.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-436730.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437110.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437140.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437230.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- criticalCVE-2026-64733: This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iP…nvd
- mediumCVE-2026-64732: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 an…nvd
- mediumCVE-2026-64730: The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPa…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30