Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted video file may lead to unexpected app termination.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write issue was addressed with improved bounds checking. Processing a maliciously crafted video file may lead to unexpected app termination, terminating the application or process. This results in a loss of availability rather than code execution or data exposure.

Affected Systems

Apple iOS, Apple iPhone OS, iOS 26.7 and 27; Apple iPadOS, iPadOS 26.7 and 27; Apple macOS, Golden Gate 27, Sequoia 15.8, and Tahoe 26.7; Apple tvOS 27; Apple visionOS 27 are all affected by this out‑of‑bounds write.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation today. The likely attack vector is local or involves a user or service processing a video file, as the description does not mention a remote exploitation condition. The risk is therefore limited to denial of service through application termination, but because the flaw affects a broad range of Apple platforms it could impact mission‑critical or enterprise devices if not patched.

Generated by OpenCVE AI on September 20, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security update for the affected versions of iOS, iPadOS, macOS, tvOS, or visionOS to fix the out‑of‑bounds write.
  • Until the update is installed, restrict processing of video files to a hardened sandbox or disable automatic playback of untrusted videos so that malformed files cannot trigger the crash.
  • Prioritize the rollout of the security update to critical or enterprise endpoints that handle video content, and schedule a rapid patch deployment.

Generated by OpenCVE AI on September 20, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Video Parsing Causes Application Crash

Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Video Processing Causing App Termination
Weaknesses CWE-119

Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Video Processing Causing App Termination
Weaknesses CWE-119

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted video file may lead to unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:39:59.386Z

Reserved: 2026-07-22T00:45:26.179Z

Link: CVE-2026-65344

cve-icon Vulnrichment

Updated: 2026-09-16T13:39:32.711Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:19.327

Modified: 2026-09-17T18:45:13.103

Link: CVE-2026-65344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:15:04Z

Weaknesses