Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of iOS 18.4 and iPadOS 18.4 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 02:48 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2025-31197An attacker on the local network may cause an unexpected app termination
  • CVE-2025-24270This issue was addressed by removing the vulnerable code
  • CVE-2025-24271An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing
  • CVE-2025-24251An attacker on the local network may cause an unexpected app termination
  • CVE-2025-24167This issue was addressed through improved state management
  • CVE-2025-30470A path handling issue was addressed with improved logic
  • CVE-2025-30427A use-after-free issue was addressed with improved memory management
  • CVE-2025-31191This issue was addressed through improved state management
  • CVE-2025-30447The issue was resolved by sanitizing logging
  • CVE-2025-24097A permissions issue was addressed with additional restrictions
  • CVE-2025-30426This issue was addressed with additional entitlement checks
  • CVE-2025-24264The issue was addressed with improved memory handling
  • CVE-2025-24212This issue was addressed with improved checks
  • CVE-2025-31183The issue was addressed with improved restriction of data container access
  • CVE-2025-30454A path handling issue was addressed with improved validation
  • CVE-2025-24211This issue was addressed with improved memory handling
  • CVE-2025-30439An attacker with physical access to a locked device may be able to view sensitive user information
  • CVE-2025-24180The issue was addressed with improved input validation
  • CVE-2025-24230An out-of-bounds read issue was addressed with improved input validation
  • CVE-2025-24210A logic error was addressed with improved error handling
  • CVE-2025-24178This issue was addressed through improved state management
  • CVE-2025-31182This issue was addressed with improved handling of symlinks
  • CVE-2025-24237A buffer overflow was addressed with improved bounds checking
  • CVE-2025-24221This issue was addressed with improved data access restriction
  • CVE-2025-30425This issue was addressed through improved state management
  • CVE-2025-30433This issue was addressed with improved access restrictions
  • CVE-2025-24190The issue was addressed with improved memory handling
  • CVE-2025-30429A path handling issue was addressed with improved validation
  • CVE-2025-24217This issue was addressed with improved redaction of sensitive information
  • CVE-2025-46308An authorization issue was addressed with improved state management
  • CVE-2025-24163The issue was addressed with improved checks
  • CVE-2025-30466A website may be able to bypass Same Origin Policy
  • CVE-2025-24203The issue was addressed with improved checks
  • CVE-2025-24192A script imports issue was addressed with improved isolation
  • CVE-2025-24238A logic issue was addressed with improved checks
  • CVE-2025-24193An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos
  • CVE-2025-24202A logging issue was addressed with improved data redaction
  • CVE-2025-24214A privacy issue was addressed by not logging contents of text fields
  • CVE-2025-24243The issue was addressed with improved memory handling
  • CVE-2025-30471A validation issue was addressed with improved logic
  • CVE-2025-30467The issue was addressed with improved checks
  • CVE-2025-30430This issue was addressed through improved state management
  • CVE-2025-24182An out-of-bounds read issue was addressed with improved input validation
  • CVE-2025-24244The issue was addressed with improved memory handling
  • CVE-2025-24205An authorization issue was addressed with improved state management
  • CVE-2025-24194A logic issue was addressed with improved checks
  • CVE-2025-24252An attacker on the local network may be able to corrupt process memory
  • CVE-2025-30456A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2025-24209A buffer overflow issue was addressed with improved memory handling
  • CVE-2025-24198An attacker with physical access may be able to use Siri to access sensitive user data

Source and provenance

Original title: About the security content of iOS 18.4 and iPadOS 18.4 - Apple Support. Captured 28 Sept 2026, 02:48 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗