Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory read and potential denial of service
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read bug in Apple operating systems allows a local user to read kernel memory and trigger an unexpected system termination; the weakness is a memory safety error (CWE-125) that can expose confidential information or destabilize the OS

Affected Systems

Apple devices running iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, or watchOS 27 are impacted; earlier releases lack the fix and remain vulnerable

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploits yet. Exploitation requires local user access to read kernel memory or induce a crash, and the CVSS score of 7.1 signals moderate severity; nevertheless, the potential for data disclosure and system instability warrants timely remediation

Generated by OpenCVE AI on September 20, 2026 at 21:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest OS update that includes the fixed versions for iOS, iPadOS, macOS, tvOS, visionOS, or watchOS
  • Restrict local user privileges to the minimum required and disable unnecessary local services until the update is applied
  • Monitor the device for kernel panics, unexpected crashes, or abnormal memory access patterns and investigate promptly if observed

Generated by OpenCVE AI on September 20, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Apple OS Allowing Kernel Memory Leakage and System Crash

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Allows Local User to Cause System Termination or Read Kernel Memory
Weaknesses CWE-119
CWE-20

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Allows Local User to Cause System Termination or Read Kernel Memory
Weaknesses CWE-119
CWE-20

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:51:43.073Z

Reserved: 2026-07-22T00:46:06.182Z

Link: CVE-2026-65359

cve-icon Vulnrichment

Updated: 2026-09-17T15:51:32.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:20.957

Modified: 2026-09-18T19:19:47.610

Link: CVE-2026-65359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:15:04Z

Weaknesses