Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-03-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel corruption or system crash
Action: Apply update
AI Analysis

Impact

An application can trigger a memory handling flaw that may lead to unexpected system termination or corruption of kernel memory. The vulnerability is a buffer overflow described by CWE‑119 and CWE‑787, which allows overwriting memory regions and potentially corrupting critical system structures. This can cause the device to crash or exhibit unstable behavior, impacting availability and integrity of the operating system.

Affected Systems

The flaw affects Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Versions prior to 26.4 are vulnerable, while iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4 and watchOS 26.4 include the fix.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity. With an EPSS score of less than 1 % and no listing in KEV, the likelihood of exploitation is currently low, but the impact if exploited is significant. Based on the description, a malicious or compromised application could exploit the flaw locally to corrupt kernel memory or force a system crash.

Generated by OpenCVE AI on March 26, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device operating system to version 26.4 or later for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. If an update is not immediately available, monitor Apple support advisories for further guidance.

Generated by OpenCVE AI on March 26, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to System Crash or Kernel Corruption in Apple Operating Systems

Thu, 26 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 14:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption Leading to System Crash or Kernel Corruption in Apple Operating Systems
Weaknesses CWE-119
CWE-787

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Title Memory Handling Issue Leading to System Crash or Kernel Corruption in Apple Platforms
Weaknesses CWE-119
CWE-122

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Title Memory Handling Issue Leading to System Crash or Kernel Corruption in Apple Platforms
Weaknesses CWE-119
CWE-122

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Wed, 25 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:13:51.466Z

Reserved: 2025-11-11T14:43:07.877Z

Link: CVE-2026-20698

cve-icon Vulnrichment

Updated: 2026-03-26T19:14:57.892Z

cve-icon NVD

Status : Modified

Published: 2026-03-25T01:17:06.540

Modified: 2026-03-26T20:16:09.580

Link: CVE-2026-20698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:20:06Z

Weaknesses