CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOS

unknownpublic exploitCVE-2026-3783CVE-2026-3784CVE-2026-4424CVE-2026-28947CVE-2026-28958CVE-2026-28973
Apple has resolved multiple vulnerabilities in iOS and iPadOS. The vulnerabilities include improper memory management such as use-after-free, buffer overflows, out-of-bounds reads and writes, integer overflows, race conditions, and insufficient input validation. These flaws can lead to unexpected crashes, memory corruption, leaking of sensitive data such as OAuth2 tokens and kernel memory, bypassing of sandbox restrictions, and in some cases execution of arbitrary code. In libcurl, OAuth2 bearer tokens can for example be leaked to a second host during HTTP(S) redirects in combination with .netrc file usage. In WebKitGTK, maliciously formatted web content and files can lead to process crashes, sandbox escapes, and data leaks. Various Apple operating systems are affected by vulnerabilities that allow applications to access sensitive user data, contact information, or system resources without proper authorization. There are also issues resolved that allowed applications to read or delete files outside their sandbox. The updates improve input validation, memory management, and security controls to mitigate these risks.

CSIRTS triage

What
Multiple memory management and input validation flaws in iOS, iPadOS, and related libraries including use-after-free, buffer overflows, integer overflows, and race conditions; libcurl OAuth2 token leakage during redirects with .netrc usage.
Who is affected
Users of iOS, iPadOS, and systems running affected versions of libcurl and WebKitGTK.
Urgency
High priority; vulnerabilities enable arbitrary code execution, sandbox escape, and sensitive data exposure including OAuth tokens and kernel memory.
Action
Update to the latest iOS, iPadOS, and libcurl versions that address CVE-2026-3783, CVE-2026-3784, CVE-2026-4424, CVE-2026-28947, CVE-2026-28958, CVE-2026-28973, CVE-2026-28979, and CVE-2026-28984.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0319

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-3783coverage & exploitation statusNVD · CVE.org
CVE-2026-3784coverage & exploitation statusNVD · CVE.org
CVE-2026-4424coverage & exploitation statusNVD · CVE.org
CVE-2026-28947coverage & exploitation statusNVD · CVE.org
CVE-2026-28958coverage & exploitation statusNVD · CVE.org
CVE-2026-28973coverage & exploitation statusNVD · CVE.org
CVE-2026-28979coverage & exploitation statusNVD · CVE.org
CVE-2026-28984coverage & exploitation statusNVD · CVE.org
CVE-2026-28990coverage & exploitation statusNVD · CVE.org
CVE-2026-28996coverage & exploitation statusNVD · CVE.org
CVE-2026-39868coverage & exploitation statusNVD · CVE.org
CVE-2026-39872coverage & exploitation statusNVD · CVE.org
CVE-2026-39877coverage & exploitation statusNVD · CVE.org
CVE-2026-43658coverage & exploitation statusNVD · CVE.org
CVE-2026-43661coverage & exploitation statusNVD · CVE.org
CVE-2026-43663coverage & exploitation statusNVD · CVE.org
CVE-2026-43667coverage & exploitation statusNVD · CVE.org
CVE-2026-43673coverage & exploitation statusNVD · CVE.org
CVE-2026-43676coverage & exploitation statusNVD · CVE.org
CVE-2026-43699coverage & exploitation statusNVD · CVE.org
CVE-2026-43700coverage & exploitation statusNVD · CVE.org
CVE-2026-43701coverage & exploitation statusNVD · CVE.org
CVE-2026-43705coverage & exploitation statusNVD · CVE.org
CVE-2026-43708coverage & exploitation statusNVD · CVE.org
CVE-2026-43711coverage & exploitation statusNVD · CVE.org
CVE-2026-43714coverage & exploitation statusNVD · CVE.org
CVE-2026-43717coverage & exploitation statusNVD · CVE.org
CVE-2026-43720coverage & exploitation statusNVD · CVE.org
CVE-2026-43722coverage & exploitation statusNVD · CVE.org
CVE-2026-43723coverage & exploitation statusNVD · CVE.org
CVE-2026-43724coverage & exploitation statusNVD · CVE.org
CVE-2026-43725coverage & exploitation statusNVD · CVE.org
CVE-2026-43726coverage & exploitation statusNVD · CVE.org
CVE-2026-43727coverage & exploitation statusNVD · CVE.org
CVE-2026-43729coverage & exploitation statusNVD · CVE.org
CVE-2026-43731coverage & exploitation statusNVD · CVE.org
CVE-2026-43733coverage & exploitation statusNVD · CVE.org
CVE-2026-43734coverage & exploitation statusNVD · CVE.org
CVE-2026-43735coverage & exploitation statusNVD · CVE.org
CVE-2026-43738coverage & exploitation statusNVD · CVE.org
CVE-2026-43742coverage & exploitation statusNVD · CVE.org
CVE-2026-43744coverage & exploitation statusNVD · CVE.org
CVE-2026-43745coverage & exploitation statusNVD · CVE.org
CVE-2026-43754coverage & exploitation statusNVD · CVE.org
CVE-2026-43757coverage & exploitation statusNVD · CVE.org
CVE-2026-43769coverage & exploitation statusNVD · CVE.org
CVE-2026-43776coverage & exploitation statusNVD · CVE.org
CVE-2026-43778coverage & exploitation statusNVD · CVE.org

+12 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories