Description
A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.
Published: 2026-07-27
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition was discovered in the filesystem integrity checks of Apple iOS and iPadOS. The flaw allows an application to create a timing gap between the check and the execution of a privileged file‑system operation, enabling it to overwrite or replace protected files. The impact is a potential compromise of system integrity or the execution of malicious code with elevated privileges, aligning with CWE‑362.

Affected Systems

Apple iOS and iPadOS devices running versions before iOS 18.7.10 or iPadOS 18.7.10 and before iOS 26.6 or iPadOS 26.6 are affected. The affected versions are inferred from the fixed‑version information included in the advisory; the CVE description does not list them explicitly. Devices running iOS 18.7.10/iPadOS 18.7.10 or later, including iOS 26.6/iPadOS 26.6, contain the race‑condition fix and are no longer vulnerable.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity; the EPSS score of less than 1 % indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The flaw is likely exploitable only with local or application‑level access, as an attacker must run code on the device to create the race condition. While the risk remains limited to devices on older firmware, any exposed system file could be modified, potentially leading to privilege escalation or persistence.

Generated by OpenCVE AI on August 18, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to iOS 18.7.10 or later, iPadOS 18.7.10 or later, including iOS 26.6 or later, to apply the race‑condition fix.
  • Ensure all third‑party applications are updated to their latest releases, as older apps might exploit this race condition.
  • Monitor device logs for unusual write attempts to protected directories and investigate any unexpected file modifications.

Generated by OpenCVE AI on August 18, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Race Condition in iOS/iPadOS Allows File System Modification

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system. A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.
References

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Race Condition in iOS/iPadOS Allows File System Modification

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Modification of Protected File System
Weaknesses CWE-284

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Modification of Protected File System
Weaknesses CWE-284
CWE-362
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Vendors & Products Apple
Apple ios And Ipados

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:49.316Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43811

cve-icon Vulnrichment

Updated: 2026-07-28T15:00:23.383Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:04.237

Modified: 2026-08-17T22:17:13.230

Link: CVE-2026-43811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')