CVE-2026-65357

Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS

A memory handling vulnerability in multiple Apple operating systems allows a local application to cause system termination or write to kernel memory.

Executive summary

A high-severity memory corruption vulnerability in Apple operating systems may allow a local application to gain unauthorized kernel memory access or crash the system.

Vulnerability

This is a memory handling flaw that permits a locally installed application with low privileges to trigger unexpected system termination or perform arbitrary writes to kernel memory, as indicated by the CVSS vector PR:L (Privileges Required: Low).

Business impact

The ability to write to kernel memory presents a significant security risk, as it can lead to full system compromise, privilege escalation, and the bypass of security boundaries. Given the CVSS score of 7.8, this vulnerability poses a high risk to organizational data integrity and system availability. Successful exploitation could allow an attacker to execute malicious code with kernel-level permissions, rendering standard user-space security controls ineffective.

Remediation

Immediate Action: Update all affected Apple devices, including iPhones, iPads, Macs, Apple TVs, Vision Pro headsets, and Apple Watches, to version 26.6 or later immediately.

Proactive Monitoring: Monitor system logs for unexpected reboots or kernel panic reports that may indicate exploitation attempts by malicious applications.

Compensating Controls: Enforce strict application vetting processes to prevent the installation of untrusted or unauthorized software, as the attack requires a local application to be present on the device.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Organizations should prioritize the deployment of the 26.6 update across their Apple device fleet to eliminate this kernel-level risk. Because this flaw allows for unauthorized kernel memory modification, immediate patching is necessary to prevent potential privilege escalation and ensure the continued integrity of system security boundaries.

More Apple CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources