What Has CERT-In Said?
In its Vulnerability Note CIVN-2026-0468, issued on September 21, CERT-In said multiple vulnerabilities in Apple products could allow a remote attacker to execute arbitrary code or cause denial-of-service (DoS) conditions on an affected system. The advisory has been rated as high severity, with CERT-In also flagging the risk of unauthorised access to sensitive information.
The advisory covers iOS versions prior to 26.7, iPadOS versions prior to 26.7, macOS Golden Gate versions prior to 27, macOS Tahoe versions prior to 26.7 and macOS Sequoia versions prior to 15.8. It also includes tvOS, watchOS and visionOS versions prior to 27, along with Safari and Xcode versions prior to 27.
CERT-In said the vulnerabilities are linked to issues including out-of-bounds read and write, integer overflow, use-after-free, type confusion, race conditions and memory corruption. The advisory also mentions authentication issues, authorisation weaknesses, permission flaws, path traversal and improper input validation.
The vulnerabilities affect both operating systems and other Apple software listed in the advisory. CERT-In has specifically identified individuals and organisations using the affected Apple operating systems and devices as the target audience for the warning.