Description
This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-06-29
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper input validation (CWE‑20). An application that triggers the flaw can corrupt kernel memory or cause the entire system to terminate unexpectedly, resulting in loss of availability and potential integrity compromise on the affected device.

Affected Systems

Apple iOS, iPadOS, and macOS devices running a system version older than 26.5.2 are vulnerable. The fix is delivered with the 26.5.2 releases for each platform.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The flaw can be leveraged only by an application that runs on the device, implying a local exploitation scenario. The vulnerability is not listed in the CISA KEV catalog, and there is no evidence of remote or privilege‑escalation capabilities in the description.

Generated by OpenCVE AI on June 30, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS, iPadOS, and macOS to version 26.5.2 or later; this update includes the necessary input‑validation fixes.
  • Avoid installing applications from untrusted or sideloaded sources; rely on the official App Store to reduce the risk of a malicious app triggering the flaw.
  • If the device is used in a development or debugging context, disable developer mode or restrict kernel‑debug permissions to limit exposure to kernel‑level exploitation pathways.

Generated by OpenCVE AI on June 30, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption and System Termination Vulnerability in Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-122

Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 29 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption and System Termination Vulnerability in Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-122

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-30T13:00:06.334Z

Reserved: 2026-04-07T19:58:20.173Z

Link: CVE-2026-39868

cve-icon Vulnrichment

Updated: 2026-06-30T12:59:19.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T16:30:16Z

Weaknesses
  • CWE-20

    Improper Input Validation