Description
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-06-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An application may trigger unexpected system termination or write kernel memory due to improper input sanitization. This flaw, classified as CWE‑20, threatens the integrity of the operating system and, based on the description, can lead to denial of service.

Affected Systems

Apple iOS and iPadOS versions prior to 18.7.10 and 26.5.2, macOS Sequoia earlier than 15.7.8, macOS Sonoma earlier than 14.8.8, macOS Tahoe earlier than 26.5.2, tvOS earlier than 26.6, visionOS earlier than 26.6, and watchOS earlier than 26.6 are vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity issue, though the EPSS score of <1% shows a low likelihood of exploitation. Attackers are expected to use a malicious or compromised application that supplies crafted input to trigger the kernel memory write. Until the updates are applied, the risk remains significant.

Generated by OpenCVE AI on August 17, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Apple operating systems to the patched releases: iOS 18.7.10, iOS 26.5.2, iPadOS 18.7.10, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6.
  • If any applications on tvOS, visionOS, or watchOS are known to trigger instability, temporarily uninstall or disable them until the OS update is applied.
  • Continuously monitor device logs for kernel panics or unexpected shutdowns, and report any anomalies to Apple for further investigation.

Generated by OpenCVE AI on August 17, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Input Sanitization Leading to Kernel Memory Write and System Termination in Apple OSes

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

Tue, 04 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple OS

Fri, 31 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple OS

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory. The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

Tue, 30 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple Operating Systems

Tue, 30 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write via Improper Input Sanitization on Apple Operating Systems

Tue, 30 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write Vulnerability in Apple iOS/iPadOS/macOS via Improper Input Handling
Weaknesses CWE-787

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 29 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Write Vulnerability in Apple iOS/iPadOS/macOS via Improper Input Handling
Weaknesses CWE-20
CWE-787

Mon, 29 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:35.040Z

Reserved: 2026-05-01T22:46:21.645Z

Link: CVE-2026-43724

cve-icon Vulnrichment

Updated: 2026-06-30T14:27:12.316Z

cve-icon NVD

Status : Modified

Published: 2026-06-29T20:17:36.837

Modified: 2026-08-17T22:17:08.607

Link: CVE-2026-43724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation