Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption or unexpected system termination
Action: Immediate Patch
AI Analysis

Impact

The CVE description indicates that an application can trigger improper memory handling in Apple operating systems, potentially leading to kernel memory corruption or unexpected system termination. This flaw can destabilize device operation, compromising kernel integrity and risking system instability.

Affected Systems

Apple’s iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to the patch releases iOS 26.6.1, iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, and watchOS 27 are potentially affected.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity vulnerability. The EPSS score is < 1%, indicating a very low exploitation probability. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local application that triggers the faulty memory handling path, so a local attacker could potentially trigger the flaw. While no public exploit is documented, the risk of kernel corruption or system crash warrants prompt attention.

Generated by OpenCVE AI on September 20, 2026 at 21:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iOS to version 26.6.1
  • Upgrade iPadOS to version 26.6.1
  • Upgrade macOS Sequoia to 15.8
  • Upgrade macOS Tahoe to 26.6.2
  • Upgrade tvOS to version 27
  • Upgrade visionOS to version 27
  • Upgrade watchOS to version 27

Generated by OpenCVE AI on September 20, 2026 at 21:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Memory Handling Vulnerability Causing Kernel Corruption and System Termination in Apple Operating Systems

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Apple OS Vulnerability: Kernel Memory Corruption and Unexpected System Termination
Weaknesses CWE-416
CWE-787

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Apple OS Vulnerability: Kernel Memory Corruption and Unexpected System Termination
Weaknesses CWE-416
CWE-787

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T14:23:34.648Z

Reserved: 2026-03-03T16:36:03.988Z

Link: CVE-2026-28935

cve-icon Vulnrichment

Updated: 2026-09-16T14:22:41.578Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:05.497

Modified: 2026-09-17T18:41:02.040

Link: CVE-2026-28935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:45:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer