Skip to finding
important · Bluetooth — Apple

A connected Bluetooth accessory can drive a 256-byte heap overwrite in Apple’s accessory-update daemon.

Affects

Apple MobileAccessoryUpdater, the accessory-firmware update service used across macOS, iOS, and iPadOS.

A malformed update asset makes uarpd allocate 64 bytes and copy 320 attacker-controlled bytes, overwriting 256 adjacent bytes.

Detail and 2 sources

Apple has published a fix.

Chain to watch
Connect an attacker-controlled accessory→↓Deliver a malformed update asset→↓Overwrite adjacent uarpd heap memory→↓Code execution and reachability from an unpaired accessory remain unproven.
Unverified chainTest pairing requirements and overwrite control across macOS, iOS and iPadOS.

The public demonstration covers corruption on macOS, not code execution, unpaired reachability, or reproduction on iOS and iPadOS.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026