Appleが不具合や脆弱性を修正した「iOS 18.7.10」と「iPadOS 18.7.10」を提供開始!26以降に非対応のiPhone XS・XRなど向け


AppleがiPhoneやiPadなど向けiOS 18.7.10とiPadOS 18.7.10をリリース!

Appleは11日(現地時間)、iPhoneおよびiPod touch向けプラットフォーム「iOS」とiPad向けプラットフォーム「iPadOS」において前バージョン「iOS 18」や「iPadOS 18」の最新版「iOS 18.7.10(22H374)」および「iPadOS 18.7.10(22H374)」を提供開始したとお知らせしています。変更点はともに不具合および脆弱性の修正が含まれているとされており、セキュリティーアップデートについてはCVEに登録されているKernel関連の「CVE-2026-43654」などの122個の脆弱性が修正されているということです。

対象機種はiOS 18やiPadOS 18の対応機種となっており、すでにiPhoneについては最新のiOS 26に対応した製品についてはiOS 18.7.7へのソフトウェア更新を選べなくなっているため、iOS 26の対象機種ではないiPhone XSやiPhone XS Max、iPhone XR向けとなっているほか、iPadについてはiPadOS 26の対象外となるiPad(第7世代)のほか、iPadOS 26の対象機種のiPad(第8世代)以降やiPad mini(第5世代)以降、iPad Air(第3世代)以降、12.9インチiPad Pro(第3世代)以降、11インチiPad Pro(第1世代)以降となっています。

Appleでは2021年に提供開始したiOS 15およびiPadOS 15から一定期間は次の最新バージョンに更新せずに既存のバージョンに留まる機能を提供しており、2025年9月に最新のiOS 26やiPadOS 26の正式版が配信開始されましたが、引き続いてしばらくiOS 18やiPadOS 18で使う場合を対象にセキュリティー修正のみを行ったソフトウェア更新を提供しており、今回、新たにiOS 18.7およびiPadOS 18.7の最新バージョンとなるiOS 18.7.10およびiPadOS 18.7.10が提供開始されました。

iOS 18やiPadOS 18の対象機種の場合には「設定」→「情報」→「ソフトウェアアップデート」から行います。単体でアップデートする場合のダウンロードサイズは手持ちのiPhone XS MaxでiOS 18.7.8からの場合では613.5MBとなっています。更新は従来通りにiTunesをインストールしたWindowsおよびMacとUSB-Lightningケーブルで接続しても実施できます。Appleが案内しているアップデートの内容およびセキュリティー修正は以下の通り。なお、これまでのAppleの動きからすると、今後もしばらくはiOS 18やiPadOS 18へのセキュリティー修正が継続して提供されると思われます。

iOS 18.7.10
このアップデートには、iPhone用のバグ修正とセキュリティアップデートが含まれています。

Appleソフトウェアアップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください: https://support.apple.com/100100

iPadOS 18.7.10
このアップデートには、iPad用のバグ修正とセキュリティアップデートが含まれています。

Appleソフトウェアアップデートのセキュリティコンテンツについては、以下のWebサイトをご覧ください: https://support.apple.com/100100

iOS 18.7.10 and iPadOS 18.7.10
Released August 17, 2026

– Accessibility
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An attacker with physical access may be able to access sensitive user data during iPhone Mirroring
 Description: This issue was addressed through improved state management.
 CVE-2026-64732: Jorge Welch (@jorgwelch)

– AirDrop
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An attacker in a privileged network position may be able to cause a denial-of-service
 Description: A reachable assertion was addressed with improved input validation.
 CVE-2026-43667: Arash Ale Ebrahim from SCy-Phy research group of CISPA Helmholtz Center for Information Security

– APFS
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64695: Narendra Singh (@_3P1C), Peter Malone

– App Store
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: This issue was addressed with improved checks.
 CVE-2026-43801: Rahul Raj

– AppleDouble
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
 Description: A buffer overflow was addressed with improved bounds checking.
 CVE-2026-43776: Peter Malone, Nicolas Rabrenovic, Irvin Wang

– Audio
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause a denial-of-service
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-64725: Seonung Park, ALTV!ST (altvi.st/)

– AVEVideoEncoder
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to execute arbitrary code with kernel privileges
 Description: A buffer overflow was addressed with improved size validation.
 CVE-2026-64747: Franco Belman at Blackwing Intelligence

– AVEVideoEncoder
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: An out-of-bounds read was addressed with improved bounds checking.
 CVE-2026-64762: Franco Belman at Blackwing Intelligence, Dun

– BackgroundAssets
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to delete files for which it does not have permission
 Description: A permissions issue was addressed with improved validation.
 CVE-2026-64707: YingQi Shi (@Mas0nShi) of DBAppSecurity’s WeBin lab

– Books
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to modify protected parts of the file system
 Description: A race condition was addressed with improved checks.
 CVE-2026-43811: Rodolphe Brunetti (@eisw0lf) of Lupus Nova

– Contacts
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to add contacts without user authorization
 Description: An authorization issue was addressed with improved validation.
 CVE-2026-64746: Rodolphe Brunetti (@eisw0lf) of Lupus Nova, Daniel Febrero

– Contacts
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted contact may leak sensitive data
 Description: The issue was addressed with improved checks.
 CVE-2026-64734: Daniel Williams

– Contacts
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access information about a user’s contacts
 Description: This issue was addressed with improved checks.
 CVE-2026-43797: Arni Hardarson (Neonix Security)

– CoreAudio
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted audio file may corrupt process memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-43673: Anonymous working with TrendAI Zero Day Initiative

– CoreAudio
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing an audio stream in a maliciously crafted media file may terminate the process
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-43744: ret2happy, Mathis Mansière, an anonymous researcher

– CoreAudio
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to cause unexpected system termination
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-43803: Rahul Raj

– CoreMedia
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted video file may lead to unexpected app termination
 Description: A memory corruption issue was addressed with improved memory handling.
 CVE-2026-43711: James Duffy (@0x4A616D657344)

– CoreUI
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted asset catalog may result in disclosure of process memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-43738: Peter Malone

– CoreVideo
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-43802: an anonymous researcher

– curl
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Authentication credentials may be sent to a server on another origin
 Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
 CVE-2026-3784
 CVE-2026-3783

– Foundation
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious app may be able to access protected user data
 Description: The issue was addressed with improved input sanitization.
 CVE-2026-43714: an anonymous researcher

– FrontBoard
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: This issue was addressed by using HTTPS when sending information over the network.
 CVE-2026-64742: Huỳnh Tấn Ngàn

– Game Center
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious app may be able to break out of its sandbox
 Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
 CVE-2026-64740: Manuel Fernandez (Stackhopper Security)

– Game Center
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to read a persistent device identifier
 Description: This issue was addressed with improved data protection.
 CVE-2026-43796: Stanislav Jelezoglo, Ilya Andr (andrd3v) of Positive Technologies

– Heimdal
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause a denial-of-service
 Description: An out-of-bounds read was addressed with improved bounds checking.
 CVE-2026-64692: Redon Gashi

– ImageIO
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted image may corrupt process memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64716: Peter Malone, Jonathan Alush-Aben, Arni Hardarson
 CVE-2026-28990: Jiri Ha, Arni Hardarson

– ImageIO
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted image may corrupt process memory
 Description: A buffer overflow issue was addressed with improved memory handling.
 CVE-2026-43661: Gandalf4a of PKU-ICODE, Anton Pakhunov, an anonymous researcher

– ImageIO
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted image may lead to arbitrary code execution
 Description: An integer overflow was addressed with improved input validation.
 CVE-2026-43818: an anonymous researcher

– ImageIO
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted image may lead to a denial-of-service
 Description: A type confusion issue was addressed with improved checks.
 CVE-2026-64693: Geonha Lee (@leegn4a)

– IOSkywalkFamily
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to disclose kernel memory
 Description: A memory corruption issue was addressed with improved memory handling.
 CVE-2026-39877: Richard Zana, Dhiyanesh Selvaraj (@redroot97)

– IOSurfaceAccelerator
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to leak sensitive kernel state
 Description: An information leakage was addressed with additional validation.
 CVE-2026-64760: Seiji Sakurai (@HeapSmasher), Franco Belman at Blackwing Intelligence, an anonymous researcher

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64749: hxr1, Hiroki Imai (LAC Co., Ltd.), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd., Ashish Kunwar

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to disclose kernel memory
 Description: An information leakage was addressed with additional validation.
 CVE-2026-64744: Ryan Hileman via Xint Code (xint.io)

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
 Description: A use after free issue was addressed with improved memory management.
 CVE-2026-43778: Ashish Kunwar, f0r of MurphySec, Mahmoud Abdelmoniem, Feng Xue and XGPT of ThreatBook, Wang Yu, Nicolas Rabrenovic, Lyutoon, Hiroki Imai (LAC Co., Ltd.), Fábio Luís @scanpt, DARKNAVY (@DarkNavyOrg), an anonymous researcher

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to bypass network filters
 Description: An inconsistent user interface issue was addressed with improved state management.
 CVE-2026-64735: Gor Aleksanyan

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: A use after free issue was addressed with improved memory management.
 CVE-2026-43822: Michal Kosiorek, Eddy Tsalolikhin
 CVE-2026-43799: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
 CVE-2026-64700: Asjid Kalam (@odinshell)

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination or write kernel memory
 Description: The issue was addressed with improved input sanitization.
 CVE-2026-43724: impost0r (ret2plt), Hyunwoo Kim (@v4bel)

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: An integer overflow was addressed with improved input validation.
 CVE-2026-43769: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to leak sensitive kernel state
 Description: The issue was addressed with improved input sanitization.
 CVE-2026-43722: Hyunwoo Kim (@v4bel), Feng Xue and XGPT of ThreatBook

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: This issue was addressed through improved state management.
 CVE-2026-64721: Lukas Gerlach

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: An out-of-bounds read was addressed with improved bounds checking.
 CVE-2026-43809: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.
 CVE-2026-43757: Wang Yu, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to leak sensitive kernel state
 Description: This issue was addressed with improved redaction of sensitive information.
 CVE-2026-43754: Ernesto Martínez García, Calif Research

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: A logic issue was addressed with improved checks.
 CVE-2026-64723: Ji’an Zhou, Mingxuan Yang, Ye Zhang

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
 Description: This issue was addressed with improved input validation.
 CVE-2026-39868: Ye Zhang (@VAR10CK) of Baidu Security, Vladislav Shevchenko (Positive Technologies), Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-43810: Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

– Kernel
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to disclose kernel memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64709: Pasquale Scola, Billy Jheng Bing Jhong and Pan Zhenpeng (@Peterpan0927) of STAR Labs SG Pte. Ltd.

– libarchive
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted file may result in disclosure of process memory
 Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
 CVE-2026-4424

– libc
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious app may be able to break out of its sandbox
 Description: An integer overflow was addressed with improved input validation.
 CVE-2026-28973: an anonymous researcher

– Libnotify
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An attacker may be able to cause unexpected app termination
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-64739: Feng Xue and XGPT of ThreatBook, Dun

– Managed Configuration
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: An authorization issue was addressed with improved state management.
 CVE-2026-64743: Daniel Febrero

– Maps
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious app may be able to break out of its sandbox
 Description: A permissions issue was addressed with additional restrictions.
 CVE-2026-64738: Robert Mindo, Nathaniel Oh (@calysteon)

– mDNSResponder
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An attacker on the local network may be able to cause a denial-of-service
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64724: Daisuke Hatakeyama (@SYZD Research)

– MediaRemote
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to gain root privileges
 Description: A path handling issue was addressed with improved validation.
 CVE-2026-43723: Richard Zana, Andreas Jaegersberger & Ro Achterberg of Nosebeard Labs

– MobileAccessoryUpdater
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious accessory may be able to cause unexpected app termination
 Description: A buffer overflow was addressed with improved bounds checking.
 CVE-2026-43807: Tristan Madani (@TristanInSec) from Talence Security

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted image may corrupt process memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-43733: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative
 CVE-2026-43729: Michael DePlante (@izobashi) of TrendAI Zero Day Initiative

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
 Description: An out-of-bounds write issue was addressed with improved input validation.
 CVE-2026-64772: wh0am1i, stratan (@5tratan)

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
 Description: An integer overflow was addressed with improved input validation.
 CVE-2026-64774: stratan (@5tratan)

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-64770: stratan (@5tratan)
 CVE-2026-64769: stratan (@5tratan)

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a 3D model may result in disclosure of process memory
 Description: A buffer overflow issue was addressed with improved memory handling.
 CVE-2026-64722: wh0am1i

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may cause an unexpected app termination
 Description: An out-of-bounds read issue was addressed with improved input validation.
 CVE-2026-64768: stratan (@5tratan)

– Model I/O
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A remote attacker may be able to cause unexpected application termination or heap corruption
 Description: A buffer overflow was addressed with improved bounds checking.
 CVE-2026-64771: wh0am1i

– Pro Res
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to cause unexpected system termination
 Description: A use after free issue was addressed with improved memory management.
 CVE-2026-43812: Francisco Knabe

– SceneKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
 Description: An out-of-bounds write issue was addressed with improved bounds checking.
 CVE-2026-64764: stratan (@5tratan)

– SceneKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
 Description: An out-of-bounds write issue was addressed by removing the vulnerable code.
 CVE-2026-64763: stratan (@5tratan)

– SceneKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
 Description: An integer overflow was addressed with improved input validation.
 CVE-2026-64766: stratan (@5tratan)
 CVE-2026-64765: stratan (@5tratan)

– Siri
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: An information disclosure issue was addressed by removing the vulnerable code.
 CVE-2026-43800: Stanislav Jelezoglo

– Storage
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: A race condition was addressed with additional validation.
 CVE-2026-28996: Alex Radocea

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: The issue was addressed with improved memory handling.
 WebKit Bugzilla: 307669
 CVE-2026-43658: Do Young Park
 WebKit Bugzilla: 318348
 CVE-2026-65338: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 313452
 CVE-2026-43795: wwwlk
 WebKit Bugzilla: 311883
 CVE-2026-28984: Artem Dinaburg of Trail of Bits via Anthropic CVD

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: This issue was addressed with improved data protection.
 WebKit Bugzilla: 311228
 CVE-2026-28958: Cantina

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A use-after-free issue was addressed with improved memory management.
 WebKit Bugzilla: 310234
 CVE-2026-28947: dr3dd
 WebKit Bugzilla: 313691
 CVE-2026-43727: Tommy DeVoss from Braze Security Team (@thedawgyg), Gurpreet Shergill, Gia Bui (@yabeow) from Calif.io

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious website may exfiltrate data cross-origin
 Description: The issue was addressed with improved checks.
 WebKit Bugzilla: 313357
 CVE-2026-43735: Rhyru9, Merrick Hare, Kwak Kiyong, Song Nuri, Khai Tran, John Lussier, Gurpreet Shergill, Drinor Selmanaj (Sentry)

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected process crash
 Description: The issue was addressed with improved memory handling.
 WebKit Bugzilla: 313528
 CVE-2026-39872: Utkarsh Pal, Ignacio Sanmillan (@ulexec)
 WebKit Bugzilla: 312781
 CVE-2026-43663: Using GLM From Z.AI, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit (@h3xr4bb1t) and NiNi (@terrynini38514) of DEVCORE Research Team, Brian Carpenter

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A memory corruption issue was addressed with improved state management.
 WebKit Bugzilla: 316791
 CVE-2026-65334: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 315082
 CVE-2026-64757: Milad Nasr and Nicholas Carlini with Claude, Anthropic

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: An out-of-bounds access issue was addressed with improved bounds checking.
 WebKit Bugzilla: 317632
 CVE-2026-64784: Janggoon Lee of Out of Bounds, OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 317231
 CVE-2026-43676: Tommy DeVoss from Braze Security Team (@thedawgyg), Mateusz Krzywicki (iVerify.io), dr3dd

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: This issue was addressed through improved state management.
 WebKit Bugzilla: 317611
 CVE-2026-65331: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 316723
 CVE-2026-65335: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 317450
 CVE-2026-65332: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 317603
 CVE-2026-65333: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 317142
 CVE-2026-65337: OpenAI Codex Security – Amy Burnett
 WebKit Bugzilla: 317349
 CVE-2026-65336: Josef Korbel
 WebKit Bugzilla: 316996
 CVE-2026-65340: Josef Korbel (Citadelo), Claudio Bozzato and Francesco Benvenuto of Cisco Talos

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: The issue was addressed with improved input validation.
 WebKit Bugzilla: 321484
 CVE-2026-64781: Thomas Guillem

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A memory corruption vulnerability was addressed with improved locking.
 WebKit Bugzilla: 321480
 CVE-2026-64782: Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to memory corruption
 Description: The issue was addressed with improved memory handling.
 WebKit Bugzilla: 318405
 CVE-2026-65341: Henock Habte

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected process crash
 Description: A use-after-free issue was addressed with improved memory management.
 WebKit Bugzilla: 316347
 CVE-2026-64715: Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative
 WebKit Bugzilla: 313693
 CVE-2026-43734: Jonathan Alush-Aben
 WebKit Bugzilla: 313857
 CVE-2026-43726: Utkarsh Pal, Tristan Madani (@TristanInSec) from Talence Security, stratan (@5tratan) of Almamater Technologies, Narendra Singh (@_3P1C), Josef Korbel (Citadelo), Gia Bui (@yabeow) from Calif.io
 WebKit Bugzilla: 317227
 CVE-2026-43699: Tommy DeVoss from Braze Security Team (@thedawgyg)
 WebKit Bugzilla: 315161
 CVE-2026-43742: Юлия Мерцалова

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: The issue was addressed with improved checks.
 WebKit Bugzilla: 316918
 CVE-2026-64780: OpenAI Codex Security – Amy Burnett

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to memory corruption
 Description: A memory corruption issue was addressed with improved memory handling.
 WebKit Bugzilla: 317317
 CVE-2026-43794: Dung Do (@_piers2) of Calif.io

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious website may be able to process restricted web content outside the sandbox
 Description: The issue was addressed with improved input validation.
 WebKit Bugzilla: 312832
 CVE-2026-43725: Luke Francis

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to memory corruption
 Description: A use-after-free issue was addressed with improved memory management.
 WebKit Bugzilla: 314115
 CVE-2026-43731: dr3dd

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to memory corruption
 Description: A type confusion issue was addressed with improved checks.
 WebKit Bugzilla: 314528
 CVE-2026-43705: dr3dd

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious website may exfiltrate data cross-origin
 Description: The issue was addressed with improved input validation.
 WebKit Bugzilla: 315306
 CVE-2026-43708: Behzad Najjarpour Jabbari (@_G4ru_)

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may disclose sensitive user information
 Description: A cross-origin issue was addressed with improved tracking of security origins.
 WebKit Bugzilla: 315368
 CVE-2026-43700: Vitaly Simonovich, Muhamad Syaiful, Christian Meurer Xavier

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: A malicious website may be able to process restricted web content outside the sandbox
 Description: The issue was addressed with improved checks.
 WebKit Bugzilla: 315004
 CVE-2026-43701: Aaron Grattafiori – NVIDIA AI Red Team

– WebKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: An out-of-bounds write issue was addressed with improved input validation.
 WebKit Bugzilla: 315365
 CVE-2026-43745: OpenAI Codex Security – Amy Burnett, Khai Tran

– WebKit Canvas
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A use-after-free issue was addressed with improved memory management.
 WebKit Bugzilla: 313175
 CVE-2026-43720: Josef Korbel, Gia Bui (@yabeow) from Calif.io

– WebKit History
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Visiting a maliciously crafted website may leak sensitive data
 Description: The issue was addressed with improved checks.
 WebKit Bugzilla: 315528
 CVE-2026-64778: Mohit Negi

– WebKit Process Model
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to read files outside of its sandbox
 Description: An access issue was addressed with improved access restrictions.
 WebKit Bugzilla: 314867
 CVE-2026-43821: Brian Carpenter

– WebKit Storage
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A memory corruption vulnerability was addressed with improved locking.
 WebKit Bugzilla: 321485
 CVE-2026-64779: Tommy DeVoss from Braze Security Team (@thedawgyg), Shubham Chaskar

– WebRTC
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: A use-after-free issue was addressed with improved memory management.
 WebKit Bugzilla: 313351
 CVE-2026-43717: Nan Wang (@eternalsakura13)

– WebRTC
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected process crash
 Description: An out-of-bounds access issue was addressed with improved bounds checking.
 WebKit Bugzilla: 317324
 CVE-2026-28979

– WebRTC
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
 Description: An out-of-bounds access issue was addressed with improved bounds checking.
 WebKit Bugzilla: 319404
 CVE-2026-64719: Shaheen Fazim

– Wi-Fi
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An attacker in physical proximity may be able to corrupt process memory
 Description: The issue was addressed with improved memory handling.
 CVE-2026-64726: Peter Malone, Mathis Mansière

– WorkoutKit
 Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
 Impact: An app may be able to access sensitive user data
 Description: An authorization issue was addressed with improved state management.
 CVE-2026-64755: Stuart Wallace

ドコモオンラインショップ
記事執筆:memn0ck

■関連リンク
エスマックス(S-MAX)
エスマックス(S-MAX) smaxjp on Twitter
S-MAX – Facebookページ
iOS 17 関連記事一覧 – S-MAX
iPadOS 17 関連記事一覧 – S-MAX
iOS 18 のアップデートについて – Apple サポート (日本)
iPadOS 18 のアップデートについて – Apple サポート (日本)
iOS 18.7.10およびiPadOS 18.7.10のセキュリティコンテンツについて – Apple サポート (日本)
Apple セキュリティアップデート – Apple サポート

コメント

タイトルとURLをコピーしました