CVE-2026-65398
Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS
An out-of-bounds access vulnerability in multiple Apple operating systems allows a local application to trigger system termination or corrupt kernel memory.
Executive summary
A critical kernel-level vulnerability in Apple software allows local applications to corrupt memory or cause system instability.
Vulnerability
This is an out-of-bounds access issue caused by insufficient bounds checking within the kernel. The vulnerability requires a low-privileged local user to execute a malicious application to trigger the flaw.
Business impact
Successful exploitation of this vulnerability allows a local attacker to corrupt kernel memory or force an unexpected system termination. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to complete loss of system integrity or availability on compromised devices. Organizations relying on these devices for sensitive operations face potential disruption and unauthorized system-level manipulation.
Remediation
Immediate Action: Update all affected Apple devices to version 27 or later immediately to apply the necessary bounds checking improvements.
Proactive Monitoring: Monitor system logs for recurring unexpected reboots or kernel panic reports that may indicate exploitation attempts.
Compensating Controls: Implement mobile device management policies that restrict the installation of untrusted or unsigned applications to reduce the likelihood of a malicious app triggering the exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates prompt attention, particularly for managed fleets of Apple devices. Administrators should prioritize the deployment of the version 27 firmware across all affected product lines. Failure to patch these devices leaves them susceptible to local memory corruption attacks that could compromise system stability and security.
More Apple CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written