Overview
- The security updates are available now over the air in Settings and via IPSW downloads, and they do not add new user-facing features.
- Apple says processing a malicious image could trigger memory corruption in ImageIO; the out-of-bounds write was fixed with improved bounds checking and the CVE credits Apple’s own teams.
- Companion patches were issued for older systems, including iPadOS 17.7.10 as well as macOS Sonoma 14.7.8 and Ventura 13.7.8, to cover devices that cannot run the newest versions.
- Eligibility includes iPhone XS and later plus a range of modern iPad models, with Apple describing the exploitation as extremely sophisticated and targeted at specific individuals.
- Reporters note these late-cycle fixes are likely among the final iOS 18 and Sequoia maintenance releases before the upcoming iOS 26 and macOS Tahoe rollouts.