NCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOS
Apple has resolved multiple vulnerabilities in iOS and iPadOS. The vulnerabilities include improper memory management such as use-after-free, buffer overflows, out-of-bounds reads and writes, integer overflows, race conditions, and insufficient input validation. These flaws can lead to unexpected crashes, memory corruption, leaking of sensitive data such as OAuth2 tokens and kernel memory, bypassing of sandbox restrictions, and in some cases execution of arbitrary code. In libcurl, OAuth2 bearer tokens can for example be leaked to a second host during HTTP(S) redirects in combination with .netrc file usage. In WebKitGTK, maliciously formatted web content and files can lead to process crashes, sandbox escapes, and data leaks. Various Apple operating systems are affected by vulnerabilities that allow applications to access sensitive user data, contact information, or system resources without proper authorization. There are also issues resolved that allowed applications to read or delete files outside their sandbox. The updates improve input validation, memory management, and security controls to mitigate these risks.
CSIRTS triage
- What
- Multiple memory management and input validation flaws in iOS, iPadOS, and related libraries including use-after-free, buffer overflows, integer overflows, and race conditions; libcurl OAuth2 token leakage during redirects with .netrc usage.
- Who is affected
- Users of iOS, iPadOS, and systems running affected versions of libcurl and WebKitGTK.
- Urgency
- High priority; vulnerabilities enable arbitrary code execution, sandbox escape, and sensitive data exposure including OAuth tokens and kernel memory.
- Action
- Update to the latest iOS, iPadOS, and libcurl versions that address CVE-2026-3783, CVE-2026-3784, CVE-2026-4424, CVE-2026-28947, CVE-2026-28958, CVE-2026-28973, CVE-2026-28979, and CVE-2026-28984.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0319
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-37830.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-37840.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-44241.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289470.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289580.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289730.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289790.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289840.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289900.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289960.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] WebKitGTK: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits VMware (07 septembre 2026)cert-fr-avis
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownUSN-8703-1: WebKitGTK vulnerabilitiesubuntu
- high[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0317 [1.00] [M/H] Vulnerabilities resolved in Apple macOSncsc-nl
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis
- mediumCVE-2026-43795: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, i…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure2026-09-14
- unknownNCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-12
- unknownNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions2026-09-12
- unknownNCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center2026-09-11
- unknownNCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center2026-09-11