CVE-2026-65375
Apple · macOS
A vulnerability in Apple macOS allows an application to trigger an unexpected system termination due to insufficient authentication checks.
Executive summary
An unauthenticated attacker can cause a denial of service on Apple macOS systems by triggering an unexpected system termination.
Vulnerability
This vulnerability involves a weakness in authentication mechanisms that allows an application to cause the operating system to terminate unexpectedly. The CVSS vector indicates the attack is network accessible and requires no authentication or user interaction.
Business impact
The primary risk posed by this vulnerability is system instability and potential denial of service. With a CVSS score of 7.5, the vulnerability is classified as High severity, as it can disrupt critical operations and lead to unplanned downtime for affected workstations or servers.
Remediation
Immediate Action: Update all affected macOS installations to version 15.8, 26.6, or 27 as specified in the official Apple security advisory.
Proactive Monitoring: Monitor system logs for repeated application crashes or unexpected kernel events that may indicate attempts to exploit this vulnerability.
Compensating Controls: Implement endpoint security policies that restrict the execution of untrusted or unauthorized applications to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for system-wide disruption, organizations should prioritize patching these macOS versions. Please ensure that all endpoints are updated immediately to version 15.8, 26.6, or 27 to effectively eliminate this denial of service risk.
More Apple CVEs all →
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written