Appleは11日(現地時間)、iPhoneおよびiPod touch向けプラットフォーム「iOS」とiPad向けプラットフォーム「iPadOS」において前バージョン「iOS 18」や「iPadOS 18」の最新版「iOS 18.7.10(22H374)」および「iPadOS 18.7.10(22H374)」を提供開始したとお知らせしています。変更点はともに不具合および脆弱性の修正が含まれているとされており、セキュリティーアップデートについてはCVEに登録されているKernel関連の「CVE-2026-43654」などの122個の脆弱性が修正されているということです。
対象機種はiOS 18やiPadOS 18の対応機種となっており、すでにiPhoneについては最新のiOS 26に対応した製品についてはiOS 18.7.7へのソフトウェア更新を選べなくなっているため、iOS 26の対象機種ではないiPhone XSやiPhone XS Max、iPhone XR向けとなっているほか、iPadについてはiPadOS 26の対象外となるiPad(第7世代)のほか、iPadOS 26の対象機種のiPad(第8世代)以降やiPad mini(第5世代)以降、iPad Air(第3世代)以降、12.9インチiPad Pro(第3世代)以降、11インチiPad Pro(第1世代)以降となっています。
Appleでは2021年に提供開始したiOS 15およびiPadOS 15から一定期間は次の最新バージョンに更新せずに既存のバージョンに留まる機能を提供しており、2025年9月に最新のiOS 26やiPadOS 26の正式版が配信開始されましたが、引き続いてしばらくiOS 18やiPadOS 18で使う場合を対象にセキュリティー修正のみを行ったソフトウェア更新を提供しており、今回、新たにiOS 18.7およびiPadOS 18.7の最新バージョンとなるiOS 18.7.10およびiPadOS 18.7.10が提供開始されました。
iOS 18やiPadOS 18の対象機種の場合には「設定」→「情報」→「ソフトウェアアップデート」から行います。単体でアップデートする場合のダウンロードサイズは手持ちのiPhone XS MaxでiOS 18.7.8からの場合では613.5MBとなっています。更新は従来通りにiTunesをインストールしたWindowsおよびMacとUSB-Lightningケーブルで接続しても実施できます。Appleが案内しているアップデートの内容およびセキュリティー修正は以下の通り。なお、これまでのAppleの動きからすると、今後もしばらくはiOS 18やiPadOS 18へのセキュリティー修正が継続して提供されると思われます。
iOS 18.7.10
このアップデートには、iPhone用のバグ修正とセキュリティアップデートが含まれています。Appleソフトウェアアップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください: https://support.apple.com/100100
iPadOS 18.7.10
このアップデートには、iPad用のバグ修正とセキュリティアップデートが含まれています。Appleソフトウェアアップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください: https://support.apple.com/100100
iOS 18.7.10 and iPadOS 18.7.10
Released August 17, 2026– Accessibility
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker with physical access may be able to access sensitive user data during iPhone Mirroring
Description: This issue was addressed through improved state management.
CVE-2026-64732: Jorge Welch (@jorgwelch)– AirDrop
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker in a privileged network position may be able to cause a denial-of-service
Description: A reachable assertion was addressed with improved input validation.
CVE-2026-43667: Arash Ale Ebrahim from SCy-Phy research group of CISPA Helmholtz Center for Information Security– APFS
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64695: Narendra Singh (@_3P1C), Peter Malone– App Store
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
CVE-2026-43801: Rahul Raj– AppleDouble
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2026-43776: Peter Malone, Nicolas Rabrenovic, Irvin Wang– Audio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/)– AVEVideoEncoder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow was addressed with improved size validation.
CVE-2026-64747: Franco Belman at Blackwing Intelligence– AVEVideoEncoder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds checking.
CVE-2026-64762: Franco Belman at Blackwing Intelligence, Dun– BackgroundAssets
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to delete files for which it does not have permission
Description: A permissions issue was addressed with improved validation.
CVE-2026-64707: YingQi Shi (@Mas0nShi) of DBAppSecurity’s WeBin lab– Books
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to modify protected parts of the file system
Description: A race condition was addressed with improved checks.
CVE-2026-43811: Rodolphe Brunetti (@eisw0lf) of Lupus Nova– Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to add contacts without user authorization
Description: An authorization issue was addressed with improved validation.
CVE-2026-64746: Rodolphe Brunetti (@eisw0lf) of Lupus Nova, Daniel Febrero– Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted contact may leak sensitive data
Description: The issue was addressed with improved checks.
CVE-2026-64734: Daniel Williams– Contacts
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access information about a user’s contacts
Description: This issue was addressed with improved checks.
CVE-2026-43797: Arni Hardarson (Neonix Security)– CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted audio file may corrupt process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43673: Anonymous working with TrendAI Zero Day Initiative– CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing an audio stream in a maliciously crafted media file may terminate the process
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-43744: ret2happy, Mathis Mansière, an anonymous researcher– CoreAudio
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected system termination
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-43803: Rahul Raj– CoreMedia
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted video file may lead to unexpected app termination
Description: A memory corruption issue was addressed with improved memory handling.
CVE-2026-43711: James Duffy (@0x4A616D657344)– CoreUI
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted asset catalog may result in disclosure of process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43738: Peter Malone– CoreVideo
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-43802: an anonymous researcher– curl
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Authentication credentials may be sent to a server on another origin
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-3784
CVE-2026-3783– Foundation
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to access protected user data
Description: The issue was addressed with improved input sanitization.
CVE-2026-43714: an anonymous researcher– FrontBoard
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed by using HTTPS when sending information over the network.
CVE-2026-64742: Huỳnh Tấn Ngàn– Game Center
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
CVE-2026-64740: Manuel Fernandez (Stackhopper Security)– Game Center
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to read a persistent device identifier
Description: This issue was addressed with improved data protection.
CVE-2026-43796: Stanislav Jelezoglo, Ilya Andr (andrd3v) of Positive Technologies– Heimdal
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause a denial-of-service
Description: An out-of-bounds read was addressed with improved bounds checking.
CVE-2026-64692: Redon Gashi– ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64716: Peter Malone, Jonathan Alush-Aben, Arni Hardarson
CVE-2026-28990: Jiri Ha, Arni Hardarson– ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process memory
Description: A buffer overflow issue was addressed with improved memory handling.
CVE-2026-43661: Gandalf4a of PKU-ICODE, Anton Pakhunov, an anonymous researcher– ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: An integer overflow was addressed with improved input validation.
CVE-2026-43818: an anonymous researcher– ImageIO
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may lead to a denial-of-service
Description: A type confusion issue was addressed with improved checks.
CVE-2026-64693: Geonha Lee (@leegn4a)– IOSkywalkFamily
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
CVE-2026-39877: Richard Zana, Dhiyanesh Selvaraj (@redroot97)– IOSurfaceAccelerator
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: An information leakage was addressed with additional validation.
CVE-2026-64760: Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence, an anonymous researcher– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64749: hxr1, Hiroki Imai (LAC Co., Ltd.), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ashish Kunwar– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: An information leakage was addressed with additional validation.
CVE-2026-64744: Ryan Hileman via Xint Code (xint.io)– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: A use after free issue was addressed with improved memory management.
CVE-2026-43778: Ashish Kunwar, f0r of MurphySec, Mahmoud Abdelmoniem, Feng Xue and XGPT of ThreatBook, Wang Yu, Nicolas Rabrenovic, Lyutoon, Hiroki Imai (LAC Co., Ltd.), Fábio Luís @scanpt, DARKNAVY (@DarkNavyOrg), an anonymous researcher– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to bypass network filters
Description: An inconsistent user interface issue was addressed with improved state management.
CVE-2026-64735: Gor Aleksanyan– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
CVE-2026-43822: Michal Kosiorek, Eddy Tsalolikhin
CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-64700: Asjid Kalam (@odinshell)– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or write kernel memory
Description: The issue was addressed with improved input sanitization.
CVE-2026-43724: impost0r (ret2plt), Hyunwoo Kim (@v4bel)– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input validation.
CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: The issue was addressed with improved input sanitization.
CVE-2026-43722: Hyunwoo Kim (@v4bel), Feng Xue and XGPT of ThreatBook– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed through improved state management.
CVE-2026-64721: Lukas Gerlach– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds checking.
CVE-2026-43809: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
CVE-2026-43757: Wang Yu, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to leak sensitive kernel state
Description: This issue was addressed with improved redaction of sensitive information.
CVE-2026-43754: Ernesto Martínez García, Calif Research– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
CVE-2026-64723: Ji’an Zhou, Mingxuan Yang, Ye Zhang– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: This issue was addressed with improved input validation.
CVE-2026-39868: Ye Zhang (@VAR10CK) of Baidu Security, Vladislav Shevchenko (Positive Technologies), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.– Kernel
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.– libarchive
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may result in disclosure of process memory
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
CVE-2026-4424– libc
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: An integer overflow was addressed with improved input validation.
CVE-2026-28973: an anonymous researcher– Libnotify
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker may be able to cause unexpected app termination
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun– Managed Configuration
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
CVE-2026-64743: Daniel Febrero– Maps
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
CVE-2026-64738: Robert Mindo, Nathaniel Oh (@calysteon)– mDNSResponder
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker on the local network may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research)– MediaRemote
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved validation.
CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs– MobileAccessoryUpdater
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious accessory may be able to cause unexpected app termination
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2026-43807: Tristan Madani (@TristanInSec) from Talence Security– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted image may corrupt process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-43733: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
CVE-2026-43729: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
Description: An out-of-bounds write issue was addressed with improved input validation.
CVE-2026-64772: wh0am1i, stratan (@5tratan)– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
Description: An integer overflow was addressed with improved input validation.
CVE-2026-64774: stratan (@5tratan)– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64770: stratan (@5tratan)
CVE-2026-64769: stratan (@5tratan)– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a 3D model may result in disclosure of process memory
Description: A buffer overflow issue was addressed with improved memory handling.
CVE-2026-64722: wh0am1i– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may cause an unexpected app termination
Description: An out-of-bounds read issue was addressed with improved input validation.
CVE-2026-64768: stratan (@5tratan)– Model I/O
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
Description: A buffer overflow was addressed with improved bounds checking.
CVE-2026-64771: wh0am1i– Pro Res
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
CVE-2026-43812: Francisco Knabe– SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CVE-2026-64764: stratan (@5tratan)– SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed by removing the vulnerable code.
CVE-2026-64763: stratan (@5tratan)– SceneKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: An integer overflow was addressed with improved input validation.
CVE-2026-64766: stratan (@5tratan)
CVE-2026-64765: stratan (@5tratan)– Siri
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An information disclosure issue was addressed by removing the vulnerable code.
CVE-2026-43800: Stanislav Jelezoglo– Storage
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with additional validation.
CVE-2026-28996: Alex Radocea– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 307669
CVE-2026-43658: Do Young Park
WebKit Bugzilla: 318348
CVE-2026-65338: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 313452
CVE-2026-43795: wwwlk
WebKit Bugzilla: 311883
CVE-2026-28984: Artem Dinaburg of Trail of Bits via Anthropic CVD– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
WebKit Bugzilla: 311228
CVE-2026-28958: Cantina– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 310234
CVE-2026-28947: dr3dd
WebKit Bugzilla: 313691
CVE-2026-43727: Tommy DeVoss from Braze Security Team (@thedawgyg), Gurpreet Shergill, Gia Bui (@yabeow) from Calif.io– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 313357
CVE-2026-43735: Rhyru9, Merrick Hare, Kwak Kiyong, Song Nuri, Khai Tran, John Lussier, Gurpreet Shergill, Drinor Selmanaj (Sentry)– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 313528
CVE-2026-39872: Utkarsh Pal, Ignacio Sanmillan (@ulexec)
WebKit Bugzilla: 312781
CVE-2026-43663: Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Brian Carpenter– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption issue was addressed with improved state management.
WebKit Bugzilla: 316791
CVE-2026-65334: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 315082
CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 317632
CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317231
CVE-2026-43676: Tommy DeVoss from Braze Security Team (@thedawgyg), Mateusz Krzywicki (iVerify.io), dr3dd– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: This issue was addressed through improved state management.
WebKit Bugzilla: 317611
CVE-2026-65331: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 316723
CVE-2026-65335: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317450
CVE-2026-65332: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317603
CVE-2026-65333: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317142
CVE-2026-65337: OpenAI Codex Security – Amy Burnett
WebKit Bugzilla: 317349
CVE-2026-65336: Josef Korbel
WebKit Bugzilla: 316996
CVE-2026-65340: Josef Korbel (Citadelo), Claudio Bozzato and Francesco Benvenuto of Cisco Talos– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 321484
CVE-2026-64781: Thomas Guillem– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321480
CVE-2026-64782: Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65341: Henock Habte– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 316347
CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
WebKit Bugzilla: 313693
CVE-2026-43734: Jonathan Alush-Aben
WebKit Bugzilla: 313857
CVE-2026-43726: Utkarsh Pal, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Narendra Singh (@_3P1C), Josef Korbel (Citadelo), Gia Bui (@yabeow) from Calif.io
WebKit Bugzilla: 317227
CVE-2026-43699: Tommy DeVoss from Braze Security Team (@thedawgyg)
WebKit Bugzilla: 315161
CVE-2026-43742: Юлия Мерцалова– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 316918
CVE-2026-64780: OpenAI Codex Security – Amy Burnett– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: A memory corruption issue was addressed with improved memory handling.
WebKit Bugzilla: 317317
CVE-2026-43794: Dung Do (@_piers2) of Calif.io– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may be able to process restricted web content outside the sandbox
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 312832
CVE-2026-43725: Luke Francis– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 314115
CVE-2026-43731: dr3dd– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to memory corruption
Description: A type confusion issue was addressed with improved checks.
WebKit Bugzilla: 314528
CVE-2026-43705: dr3dd– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may exfiltrate data cross-origin
Description: The issue was addressed with improved input validation.
WebKit Bugzilla: 315306
CVE-2026-43708: Behzad Najjarpour Jabbari (@_G4ru_)– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cross-origin issue was addressed with improved tracking of security origins.
WebKit Bugzilla: 315368
CVE-2026-43700: Vitaly Simonovich, Muhamad Syaiful, Christian Meurer Xavier– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: A malicious website may be able to process restricted web content outside the sandbox
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315004
CVE-2026-43701: Aaron Grattafiori – NVIDIA AI Red Team– WebKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds write issue was addressed with improved input validation.
WebKit Bugzilla: 315365
CVE-2026-43745: OpenAI Codex Security – Amy Burnett, Khai Tran– WebKit Canvas
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313175
CVE-2026-43720: Josef Korbel, Gia Bui (@yabeow) from Calif.io– WebKit History
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Visiting a maliciously crafted website may leak sensitive data
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 315528
CVE-2026-64778: Mohit Negi– WebKit Process Model
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to read files outside of its sandbox
Description: An access issue was addressed with improved access restrictions.
WebKit Bugzilla: 314867
CVE-2026-43821: Brian Carpenter– WebKit Storage
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A memory corruption vulnerability was addressed with improved locking.
WebKit Bugzilla: 321485
CVE-2026-64779: Tommy DeVoss from Braze Security Team (@thedawgyg), Shubham Chaskar– WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313351
CVE-2026-43717: Nan Wang (@eternalsakura13)– WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 317324
CVE-2026-28979– WebRTC
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: An out-of-bounds access issue was addressed with improved bounds checking.
WebKit Bugzilla: 319404
CVE-2026-64719: Shaheen Fazim– Wi-Fi
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An attacker in physical proximity may be able to corrupt process memory
Description: The issue was addressed with improved memory handling.
CVE-2026-64726: Peter Malone, Mathis Mansière– WorkoutKit
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
CVE-2026-64755: Stuart Wallace
■関連リンク
・エスマックス(S-MAX)
・エスマックス(S-MAX) smaxjp on Twitter
・S-MAX – Facebookページ
・iOS 17 関連記事一覧 – S-MAX
・iPadOS 17 関連記事一覧 – S-MAX
・iOS 18 のアップデートについて – Apple サポート (日本)
・iPadOS 18 のアップデートについて – Apple サポート (日本)
・iOS 18.7.10およびiPadOS 18.7.10のセキュリティコンテンツについて – Apple サポート (日本)
・Apple セキュリティアップデート – Apple サポート






コメント