Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Updates
AI Analysis

Impact

An out‑of‑bounds write flaw exists in the file‑processing component of Apple operating systems. The weakness is a classic buffer bounds violation (CWE‑787). When a maliciously crafted file is processed, the flaw causes an unexpected application termination rather than normal operation, leading to a denial of service within the affected application.

Affected Systems

Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, and visionOS 27 are vulnerable. The issue is removed in the higher releases listed in the vendor advisories; earlier versions remain susceptible.

Risk and Exploitability

The CVSS score of 4.3 signals a low severity impact. The EPSS score of less than 1% indicates a very low probability of mass exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a specially crafted file that is processed locally; no elevated privileges or network access are described, so the attack vector is likely limited to local or user‑initiated file handling. Though unlikely to affect a large number of systems, the impact is real for users who run applications that process untrusted files and which may experience involuntary service interruption.

Generated by OpenCVE AI on September 20, 2026 at 20:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the vendor‑supplied updates – iOS 26.7 or later, iPadOS 26.7 or later, macOS Golden Gate 27 or later (including Sequoia 15.8, Tahoe 26.7), tvOS 27, and visionOS 27 – which patch the bounds‑checking flaw.
  • Restrict the processing of untrusted files by enabling sandboxing or disabling features that allow arbitrary file opening, thereby limiting the ability of a malicious file to trigger the crash.
  • Monitor system logs for repeated crashes or abnormal file‑handling events and report such incidents to Apple support to aid in early detection of exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Crashes Applications in Apple Operating Systems

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in File Processing Leads to Application Crash
Weaknesses CWE-787

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in File Processing Leads to Application Crash
Weaknesses CWE-787

Mon, 14 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:23:12.028Z

Reserved: 2026-03-03T16:36:03.992Z

Link: CVE-2026-28966

cve-icon Vulnrichment

Updated: 2026-09-17T16:23:04.154Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:05.930

Modified: 2026-09-18T19:22:45.463

Link: CVE-2026-28966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses