Description
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in Apple’s operating system state handling can allow a malicious or untrusted application to trigger unexpected system termination or create the possibility of writing to kernel memory. This flaw can lead to denial‑of‑service by crashing the device and may grant elevated privileges if an attacker succeeds at corrupting kernel objects, compromising confidentiality, integrity, and availability of the affected device.

Affected Systems

Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and watchOS 26.6 are affected. The vulnerability is tied to the operating system kernel and the broader platform stack, impacting all devices running these versions.

Risk and Exploitability

With a CVSS score of 9.8 and an EPSS score of < 1%, the vulnerability is high severity but with a very low probability of exploitation. Because the defect permits writing to kernel memory, the potential impact is severe. Exploitation would likely require a specially crafted local application or code executed with elevated privileges. Since the bug is fixed in the mentioned updates the risk is contingent on whether an affected device has attempted to install the update. The lack of a KEV listing suggests no public exploit code is known, but the severity of kernel corruption warrants caution.

Generated by OpenCVE AI on August 3, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest available update for your Apple device: iOS 26.6 or iPadOS 26.6 on iPhones and iPads, Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6 on macOS, and watchOS 26.6 on Apple Watches.
  • If a device cannot receive the latest OS update, contact Apple Support for guidance, and consider upgrading hardware if the OS cannot be installed.
  • Enable automatic software updates so that future patches are applied automatically.

Generated by OpenCVE AI on August 3, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Race Condition Threatening Kernel Memory and System Stability in Apple iOS, macOS, watchOS

Sun, 02 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Kernel Memory Corruption and Potential System Termination in Apple Operating Systems
Weaknesses CWE-469

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Kernel Memory Corruption and Potential System Termination in Apple Operating Systems
Weaknesses CWE-362
CWE-469
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:35:20.451Z

Reserved: 2026-05-01T22:46:27.821Z

Link: CVE-2026-43805

cve-icon Vulnrichment

Updated: 2026-07-28T14:35:15.238Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:03.747

Modified: 2026-07-28T18:57:06.837

Link: CVE-2026-43805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:45:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')