Update Now: iOS 18.4.1 and macOS Sequoia 15.4.1 Address Actively Exploited Vulnerabilities - MacRumors
Skip to Content

Update Now: iOS 18.4.1 and macOS Sequoia 15.4.1 Address Actively Exploited Vulnerabilities

The iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, and visionOS 2.4.1 updates that Apple released today include fixes for two major vulnerabilities, which means you should install the new software as soon as you can.

bug security vulnerability issue fix larry
According to Apple, it is aware of reports that these vulnerabilities may have been actively exploited in the wild. Apple says that the security flaws were potentially used in an "extremely sophisticated attack against specific targeted individuals."

One of the issues impacts CoreAudio, and involves a maliciously crafted audio file. Processing the audio stream in the media file could result in code execution. Apple fixed the memory corruption issue with improved bounds checking.

The other vulnerability affected pointer authentication code, and an attacker with arbitrary read and write capability could bypass the Pointer Authentication features that prevent memory from being tampered with. Apple removed the vulnerable code to prevent the exploit from working.

All of the updates are available today, and focus primarily on the security fixes. iOS 18.4.1 also addresses an issue that could prevent some wireless CarPlay setups from working properly in select vehicles.

Related Forums: iOS 18, iPadOS 18, macOS Sequoia

Popular Stories

Apple Event Logo

Apple's Next Era Begins September 1

Thursday May 7, 2026 10:36 am PDT by
Apple recently announced that Tim Cook will be stepping down as CEO later this year, after 15 years of leading the company. Effective September 1, Apple's hardware engineering chief John Ternus will become the company's next CEO, while Cook will become executive chairman of Apple's board of directors. In his new role, Apple said Cook will assist with "certain aspects" of the company,...
Instagram Feature 2

PSA: Instagram Encrypted Messaging Ends on Friday, May 8

Tuesday May 5, 2026 8:24 am PDT by
Instagram will remove end-to-end encryption for direct messages between users from May 8, 2026. When the date comes around, Meta will potentially be able to see the contents of all messages between users on the social media platform. Encrypting messages has been an optional feature in Instagram since 2023, but in March of this year the social media platform quietly updated a help page to say ...
Apple Event Logo

Apple Just Released a New Accessory

Monday May 4, 2026 8:13 am PDT by
Apple today released a new Pride Edition Sport Loop for the Apple Watch. The band features a rainbow design with 11 colors of woven nylon yarns. The new Pride Edition Sport Loop is available to order now on Apple.com and in the Apple Store app in 40mm, 42mm, and 46mm sizes, and it will be available at Apple Store locations starting later this week. In the U.S., the band costs $49. There...

Top Rated Comments

14 months ago

Instead of 'this affected only a small amount/handful of users' they changed their text to sophisticated attacks against specific individuals. Classic Apple Marketing.
Sure, but this description is also arguably better for describing state sponsored targeted attacks.
Score: 14 Votes (Like | Disagree)
VictoryHighway Avatar
14 months ago

I hope some day this type of updates are released as a “rapid security response”
Yeah. Whatever happened to those?
Score: 13 Votes (Like | Disagree)
14 months ago
I hope some day this type of updates are released as a “rapid security response”
Score: 12 Votes (Like | Disagree)
hoodafoo Avatar
14 months ago

Has anyone actually ever been hacked? Still rolling on 16.7.2 on my 14 pro…. You don’t ever see any horror stories of people having their iPhone hacked because they didn’t update. At least I haven’t.
It just means you're not important
Score: 9 Votes (Like | Disagree)
jz0309 Avatar
14 months ago
Obliged.
I like security and bug fixes
Score: 9 Votes (Like | Disagree)
jayducharme Avatar
14 months ago
Weird: after the update, I'm no longer receiving 2-factor authentication texts. I tried rebooting, but no luck. I'm still getting regular messages though.

Never mind. I'm a dope. After the last power-down I forgot to turn my iPhone back on. Everything's working fine.
Score: 6 Votes (Like | Disagree)