BlackTreeCVE IntelligenceOfficial source evidencesupport.apple.comVersioned article
Official source article · support.apple.com
About the security content of iOS 18.4 and iPadOS 18.4 - Apple Support
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot28 Sept 2026, 02:48 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2025-31197An attacker on the local network may cause an unexpected app termination
- CVE-2025-24270This issue was addressed by removing the vulnerable code
- CVE-2025-24271An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing
- CVE-2025-24251An attacker on the local network may cause an unexpected app termination
- CVE-2025-24167This issue was addressed through improved state management
- CVE-2025-30470A path handling issue was addressed with improved logic
- CVE-2025-30427A use-after-free issue was addressed with improved memory management
- CVE-2025-31191This issue was addressed through improved state management
- CVE-2025-30447The issue was resolved by sanitizing logging
- CVE-2025-24097A permissions issue was addressed with additional restrictions
- CVE-2025-30426This issue was addressed with additional entitlement checks
- CVE-2025-24264The issue was addressed with improved memory handling
- CVE-2025-24212This issue was addressed with improved checks
- CVE-2025-31183The issue was addressed with improved restriction of data container access
- CVE-2025-30454A path handling issue was addressed with improved validation
- CVE-2025-24211This issue was addressed with improved memory handling
- CVE-2025-30439An attacker with physical access to a locked device may be able to view sensitive user information
- CVE-2025-24180The issue was addressed with improved input validation
- CVE-2025-24230An out-of-bounds read issue was addressed with improved input validation
- CVE-2025-24210A logic error was addressed with improved error handling
- CVE-2025-24178This issue was addressed through improved state management
- CVE-2025-31182This issue was addressed with improved handling of symlinks
- CVE-2025-24237A buffer overflow was addressed with improved bounds checking
- CVE-2025-24221This issue was addressed with improved data access restriction
- CVE-2025-30425This issue was addressed through improved state management
- CVE-2025-30433This issue was addressed with improved access restrictions
- CVE-2025-24190The issue was addressed with improved memory handling
- CVE-2025-30429A path handling issue was addressed with improved validation
- CVE-2025-24217This issue was addressed with improved redaction of sensitive information
- CVE-2025-46308An authorization issue was addressed with improved state management
- CVE-2025-24163The issue was addressed with improved checks
- CVE-2025-30466A website may be able to bypass Same Origin Policy
- CVE-2025-24203The issue was addressed with improved checks
- CVE-2025-24192A script imports issue was addressed with improved isolation
- CVE-2025-24238A logic issue was addressed with improved checks
- CVE-2025-24193An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos
- CVE-2025-24202A logging issue was addressed with improved data redaction
- CVE-2025-24214A privacy issue was addressed by not logging contents of text fields
- CVE-2025-24243The issue was addressed with improved memory handling
- CVE-2025-30471A validation issue was addressed with improved logic
- CVE-2025-30467The issue was addressed with improved checks
- CVE-2025-30430This issue was addressed through improved state management
- CVE-2025-24182An out-of-bounds read issue was addressed with improved input validation
- CVE-2025-24244The issue was addressed with improved memory handling
- CVE-2025-24205An authorization issue was addressed with improved state management
- CVE-2025-24194A logic issue was addressed with improved checks
- CVE-2025-24252An attacker on the local network may be able to corrupt process memory
- CVE-2025-30456A parsing issue in the handling of directory paths was addressed with improved path validation
- CVE-2025-24209A buffer overflow issue was addressed with improved memory handling
- CVE-2025-24198An attacker with physical access may be able to use Siri to access sensitive user data
Source and provenance
Original title: About the security content of iOS 18.4 and iPadOS 18.4 - Apple Support. Captured 28 Sept 2026, 02:48 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗