Description
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unexpected System Termination
Action: Update Systems
AI Analysis

Impact

The vulnerability is a race condition (identified as CWE-362) that can cause the operating system to terminate unexpectedly when an application triggers rapid, concurrent state changes. An application may exploit the improper handling of concurrent operations to provoke this termination. The effect is a sudden loss of system availability, with no immediate threat to data confidentiality or integrity evident from the description.

Affected Systems

Apple operating systems are affected, including iOS 26.7, iOS 27, iPadOS 26.7, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Devices running any of these versions may be vulnerable.

Risk and Exploitability

The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting no known public exploits malicious or poorly written application that launches concurrent operations to trigger the race condition. Because the flaw can cause a system crash, its impact is reflected in potential loss of service. The exact likelihood of exploitation cannot be quantified, but the absence of known exploits and the possibility of a client‑side trigger suggest a moderate to high risk depending on exposure to third‑party apps. Based on the description, the likely attack vector is an application that initiates rapid, concurrent state changes, inferred from the race‑condition nature of the flaw.

Generated by OpenCVE AI on September 20, 2026 at 19:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iOS devices to iOS 26.7, iOS 27, or later to include the race‑condition fix.
  • Upgrade iPadOS devices to iPadOS 26.7, iPadOS 27, or later.
  • Upgrade macOS machines to macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, or later.
  • Upgrade watchOS devices to version 27 or later.
  • Upgrade tvOS and visionOS devices to version 27 or later.

Generated by OpenCVE AI on September 20, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Unexpected System Termination Across Apple OS Versions
Weaknesses CWE-362

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Race Condition Allowing Unexpected System Termination Across Apple OS Versions
Weaknesses CWE-362

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T16:22:27.863Z

Reserved: 2026-07-22T00:46:06.182Z

Link: CVE-2026-65360

cve-icon Vulnrichment

Updated: 2026-09-17T16:22:22.309Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:21.067

Modified: 2026-09-18T19:18:49.260

Link: CVE-2026-65360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')