Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apple Multiple Products Font Processing Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A vulnerability exists in several Apple products, including iOS, iPadOS, macOS, tvOS, and watchOS, where processing a font file can result in arbitrary code execution. This issue has been actively exploited in versions of iOS prior to 15.7.1. The vulnerability arises from improper cache handling in the FontParser component.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected device.

Remediation

Users can update to the latest versions of the operating system to address this vulnerability. The patched versions are iOS 16.3.8 and iPadOS 16.3.8, macOS Ventura 13.2, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, tvOS 16.3, and watchOS 9.3.

Added: May 15, 2026, 11:08 AM
Updated: May 15, 2026, 11:08 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
5.3
remediation
7.7
relevance
0.0
threat
8.1
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.