Description
This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-06-29
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient input validation, allowing an application to send data that is not properly checked before use. This flaw can lead to corrupt kernel memory or cause the operating system to terminate unexpectedly. An exploitation path is possible if an application supplies malicious input, potentially triggering a kernel memory overwrite or a system crash, which results in loss of availability and possible integrity compromise on the affected device.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices running any version older than the patched releases are vulnerable. The fix is delivered with iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The flaw can be leveraged only by an application that runs on the device, implying a local exploitation scenario. The vulnerability is not listed in the CISA KEV catalog, and there is no evidence of remote or privilege‑escalation capabilities in the description.

Generated by OpenCVE AI on August 4, 2026 at 08:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to the latest patched releases: iOS and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6.
  • Avoid installing applications from untrusted or sideloaded sources; rely on the official App Store to reduce the risk of a malicious app triggering the flaw.
  • If the device is used in a development or debugging context, disable developer mode or restrict kernel‑debug permissions to limit exposure to kernel‑level exploitation pathways.

Generated by OpenCVE AI on August 4, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption via Improper Input Validation

Sun, 02 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption via Improper Input Validation

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or corrupt kernel memory. This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption and System Termination Vulnerability in Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-122

Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 29 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption and System Termination Vulnerability in Apple iOS, iPadOS, and macOS
Weaknesses CWE-119
CWE-122

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-27T20:14:33.242Z

Reserved: 2026-04-07T19:58:20.173Z

Link: CVE-2026-39868

cve-icon Vulnrichment

Updated: 2026-06-30T12:59:19.543Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:33.930

Modified: 2026-07-27T21:16:51.020

Link: CVE-2026-39868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation