Description
The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-06-29
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient input sanitization, allowing untrusted data to dictate writes to kernel memory. An attacker could target an application to trigger the flaw, resulting in unexpected system termination or a corrupt kernel state that may be leveraged for code execution. The primary impact is the ability to modify critical memory structures within the operating system, effectively granting attackers full control over the device.

Affected Systems

Apple iOS, iPadOS, and macOS devices running versions prior to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 are affected. The issue is fixed in those release versions, so any device not updated to these builds remains vulnerable.

Risk and Exploitability

The lack of a public EPSS score or inclusion in CISA KEV makes the exact likelihood of exploitation uncertain, but the described kernel memory write represents a high‑severity flaw. Based on description the likely attack vector is via a malicious or compromised application that supplies crafted input, thereby triggering the kernel write. Because no CVSS score is provided, the risk assessment relies on the criticality of the kernel write and the potential for arbitrary code execution. Until devices are updated, any application that can be controlled by an attacker constitutes a plausible path to exploit the flaw.

Generated by OpenCVE AI on June 29, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Apple devices to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 to receive the input‑sanitization fix.
  • If certain applications are known to trigger instability, temporarily uninstall or disable them until the OS is patched.
  • Continuously monitor device logs for unexpected kernel panics or crashes and report any findings to Apple for further investigation.

Generated by OpenCVE AI on June 29, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write Vulnerability in Apple iOS/iPadOS/macOS via Improper Input Handling
Weaknesses CWE-20
CWE-787

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-29T19:42:59.606Z

Reserved: 2026-05-01T22:46:21.645Z

Link: CVE-2026-43724

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T21:45:04Z

Weaknesses