Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of iOS 18.7.7 and iPadOS 18.7.7 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs26

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-14524bearer token leak on cross-protocol redirect
  • CVE-2026-28886A null pointer dereference was addressed with improved input validation
  • CVE-2026-28864A local attacker may gain access to user's Keychain items
  • CVE-2026-20668A logging issue was addressed with improved data redaction
  • CVE-2026-20687A use after free issue was addressed with improved memory management
  • CVE-2026-28868A logging issue was addressed with improved data redaction
  • CVE-2026-28852A stack overflow was addressed with improved input validation
  • CVE-2026-20665This issue was addressed through improved state management
  • CVE-2026-20690An out-of-bounds access issue was addressed with improved bounds checking
  • CVE-2026-28865An attacker in a privileged network position may be able to intercept network traffic
  • CVE-2026-28878A privacy issue was addressed by removing sensitive data
  • CVE-2026-20643Processing maliciously crafted web content may bypass Same Origin Policy
  • CVE-2026-28967An attacker in a privileged network position may be able to cause a denial-of-service
  • CVE-2026-28879A use-after-free issue was addressed with improved memory management
  • CVE-2026-28880A permissions issue was addressed with additional restrictions
  • CVE-2026-20637A use after free issue was addressed with improved memory management
  • CVE-2026-28876A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-28860A local attacker may be able to modify the state of the Keychain
  • CVE-2026-28861A logic issue was addressed with improved state management
  • CVE-2026-20657A buffer overflow issue was addressed with improved memory handling
  • CVE-2026-28866This issue was addressed with improved validation of symlinks
  • CVE-2026-28867This issue was addressed with improved authentication
  • CVE-2026-28871Visiting a maliciously crafted website may lead to a cross-site scripting attack
  • CVE-2025-43534A user with physical access to an iOS device may be able to bypass Activation Lock
  • CVE-2025-43376A remote attacker may be able to view leaked DNS queries with Private Relay turned on
  • CVE-2025-64505LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index

Source and provenance

Original title: About the security content of iOS 18.7.7 and iPadOS 18.7.7 - Apple Support. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗