Description
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to system crash
Action: Immediate Patch
AI Analysis

Impact

A fault in Apple’s operating systems introduces an out‑of‑bounds access due to missing bounds checking, enabling a malicious app to read or write beyond allocated memory. The flaw occurs in kernel code, so the attacker could cause the system to terminate unexpectedly or corrupt critical kernel structures, resulting in denial of service or kernel memory corruption.

Affected Systems

The vulnerability affects all Apple operating systems including iOS, iPadOS, macOS Golden Gate, tvOS, visionOS and watchOS on devices running a version earlier than 27. Apple has released version 27 of each of those systems with the fix applied.

Risk and Exploitability

The kernel‑level nature of the bug indicates a high severity. A malicious application may be able to trigger unexpected system termination or corrupt kernel memory. The EPSS score of < 1% suggests a very low exploitation probability. The issue is not listed in the CISA KEV catalog, but the potential for system crash or kernel corruption warrants treating it as a high‑risk vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 19:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Apple update to iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, or watchOS 27, depending on the device type.
  • After deployment, monitor kernel logs for unexpected crashes or memory corruption errors to validate system stability.
  • If an update cannot be applied immediately, limit the installation of third‑party applications, enforce device encryption, and consider network segmentation to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Access Leading to Kernel Memory Corruption in Apple OS

Wed, 16 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access Allowing Kernel Memory Corruption on Apple OS
Weaknesses CWE-122
CWE-787

Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Access Allowing Kernel Memory Corruption on Apple OS
Weaknesses CWE-122
CWE-787

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T03:57:17.932Z

Reserved: 2026-07-22T00:46:56.740Z

Link: CVE-2026-65398

cve-icon Vulnrichment

Updated: 2026-09-16T17:37:46.407Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:23.200

Modified: 2026-09-17T04:17:55.233

Link: CVE-2026-65398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:15:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')