Description
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An assertion failure reachable through malformed input was discovered in certain Apple iOS and iPadOS versions. The flaw originates from insufficient input validation that allows an attacker to trigger a defensive assertion, causing the system to crash and halt normal operation. The result is a denial‑of‑service, preventing legitimate use of the affected device until it is restarted.

Affected Systems

The vulnerability impacts all Apple iOS and iPadOS releases older than 18.7.10. The fix was incorporated in iOS 18.7.10 and iPadOS 18.7.10, which address the input‑validation issue.

Risk and Exploitability

Based on the description, it is inferred that an attacker must be in a privileged position on the same network as the device to send specially crafted input. The EPSS score is not available and the flaw is not listed in CISA KEV, suggesting that there are no known public exploits, but the limited attack surface still warrants remediation. A crash can disrupt device availability until a reboot occurs.

Generated by OpenCVE AI on August 17, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Apple software update to iOS 18.7.10 or iPadOS 18.7.10 to fix the input‑validation flaw.
  • Restrict the device from acting as a privileged network host or isolate it from networks where an attacker could send malformed packets.
  • Configure monitoring to detect unexpected reboots or crashes and respond promptly.

Generated by OpenCVE AI on August 17, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Reachable Assertion in iOS and iPadOS
Weaknesses CWE-20

Mon, 17 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.
References

Subscriptions

Apple Ios And Ipados
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:35.370Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T22:17:06.420

Modified: 2026-08-17T22:17:06.420

Link: CVE-2026-43667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:15:04Z

Weaknesses
  • CWE-20

    Improper Input Validation