Description
The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-06-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by insufficient input sanitization, which allows untrusted data to be used for writes to kernel memory. An attacker targeting an application could trigger the flaw, leading to unexpected system termination or corruption of kernel memory.

Affected Systems

Apple iOS, iPadOS, and macOS devices running versions prior to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 are affected. The issue is fixed in those release versions, so any device not updated to these builds remains vulnerable.

Risk and Exploitability

The EPSS score is < 1% and the CVSS score of 7.8 indicates a high‑severity flaw. The likely attack vector is through a malicious or compromised application that supplies crafted input, which could trigger the kernel write. The risk assessment considers the possibility of unexpected shutdowns or kernel corruption. Until devices are updated, any application that can be controlled by an attacker remains a potential exploitation path.

Generated by OpenCVE AI on June 30, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Apple devices to iOS 26.5.2, iPadOS 26.5.2, and macOS Tahoe 26.5.2 to receive the input‑sanitization fix.
  • If certain applications are known to trigger instability, temporarily uninstall or disable them until the OS is patched.
  • Continuously monitor device logs for unexpected kernel panics or crashes and report any findings to Apple for further investigation.

Generated by OpenCVE AI on June 30, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple Operating Systems

Tue, 30 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple Operating Systems

Tue, 30 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write Vulnerability in Apple iOS/iPadOS/macOS via Improper Input Handling
Weaknesses CWE-787

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write Vulnerability in Apple iOS/iPadOS/macOS via Improper Input Handling
Weaknesses CWE-20
CWE-787

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.
References

Subscriptions

Apple Ios And Ipados Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-06-30T20:03:10.792Z

Reserved: 2026-05-01T22:46:21.645Z

Link: CVE-2026-43724

cve-icon Vulnrichment

Updated: 2026-06-30T14:27:12.316Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T22:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation