March 24, 2026
Apple Patches Critical Security Flaws in iOS 18.7.7 and iPadOS 18.7.7

Apple Patches Critical Security Flaws in iOS 18.7.7 and iPadOS 18.7.7

Posted 1 hour ago by
Apple has released iOS 18.7.7 and iPadOS 18.7.7, providing a substantial list of security fixes for older devices that do not support the latest iOS 26 operating system.

Apple Patches Critical Security Flaws in iOS 18.7.7 and iPadOS 18.7.7

Available for the iPhone XS, iPhone XS Max, iPhone XR, and the seventh-generation iPad, this maintenance update carries build number 22H333. It arrives alongside today's broader public rollout of iOS 26.4. Users can download the update over the air through the Software Update menu in Settings.


For those who prefer a manual installation, direct links are available on our Where to Download iPhone Firmware Files From and Where To Download iPad Firmware Files From pages. You can also quickly find the correct file for your specific device using the iClarified IPSW Wizard.

Apple strongly recommends this update for all eligible users, as it addresses over two dozen vulnerabilities across the system, including patches for the kernel, WebKit, and various network protocols.

Here are the security fixes included in the release:
• 802.1X: An authentication issue was addressed with improved state management to prevent an attacker in a privileged network position from intercepting traffic (CVE-2026-28865).
• AppleKeyStore: A use after free issue was addressed with improved memory management (CVE-2026-20637).
• Audio: A use-after-free issue was addressed with improved memory management (CVE-2026-28879).
• Clipboard: An issue allowing an app to access sensitive user data was addressed with improved validation of symlinks (CVE-2026-28866).
• CoreMedia: An out-of-bounds access issue was addressed with improved bounds checking (CVE-2026-20690).
• CoreUtils: A null pointer dereference was addressed with improved input validation (CVE-2026-28886).
• Crash Reporter: A privacy issue was addressed by removing sensitive data to prevent apps from enumerating installed apps (CVE-2026-28878).
• curl: A vulnerability in open source code was addressed (CVE-2025-14524).
• DeviceLink: A parsing issue in the handling of directory paths was addressed with improved path validation (CVE-2026-28876).
• Focus: A logging issue was addressed with improved data redaction (CVE-2026-20668).
• iCloud: A permissions issue was addressed with additional restrictions (CVE-2026-28880).
• ImageIO: A vulnerability in open source code was addressed (CVE-2025-64505).
• iTunes Store: A path handling issue was addressed with improved validation, preventing a local attacker from bypassing Activation Lock (CVE-2025-43534).
• Kernel: A logging issue was addressed with improved data redaction (CVE-2026-28868).
• Kernel: An issue allowing an app to leak sensitive kernel state was addressed with improved authentication (CVE-2026-28867).
• Kernel: A use after free issue was addressed with improved memory management to prevent unexpected system termination or kernel memory writing (CVE-2026-20687).
• mDNSResponder: An issue allowing an app to leak sensitive kernel state was addressed with improved authentication (CVE-2026-28867).
• Security: An issue allowing a local attacker to access Keychain items was addressed with improved permissions checking (CVE-2026-28864).
• UIFoundation: A stack overflow was addressed with improved input validation (CVE-2026-28852).
• Vision: An issue parsing a maliciously crafted file was addressed with improved memory handling (CVE-2026-20657).
• WebKit: An issue preventing Content Security Policy enforcement was addressed through improved state management (CVE-2026-20665).
• WebKit: A cross-origin issue in the Navigation API was addressed with improved input validation (CVE-2026-20643).
• WebKit: A logic issue was addressed with improved state management to prevent remote attackers from viewing leaked DNS queries with Private Relay turned on (CVE-2025-43376).
• WebKit: A logic issue was addressed with improved state management preventing malicious websites from accessing script message handlers intended for other origins (CVE-2026-28861).
• WebKit: A logic issue was addressed with improved checks to prevent cross-site scripting attacks (CVE-2026-28871).
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments
You must login or register to add a comment...
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Sequoia
Where to Download macOS Sonoma
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS