Description
The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Crash)
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when an application can trigger unexpected system termination due to missing runtime checks in the operating system. Based on the description, it is inferred that the flaw allows a calling application to force a crash, which translates to a denial of service affecting device availability. The weakness aligns with the CWE-248 and CWE-400 designations for unexpected behavior and resource exhaustion, respectively.

Affected Systems

Apple's iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. Versions prior to iOS 26.7 or 27, iPadOS 26.7 or 27, macOS Golden Gate 27 or earlier, macOS Tahoe 26.7 or earlier, and tvOS, visionOS, watchOS version 27 or earlier are vulnerable. The flaw is fixed in the listed releases of each operating system.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑impact denial of service, while the EPSS score of less than 1 % shows that public exploitation is unlikely at this time and the flaw is not cataloged in the CISA KEV list. The description does not specify a remote attack surface; therefore, it is inferred that the most plausible vector is local or application‑based, meaning that any third‑party application with execution privileges could exploit the flaw to crash the device.

Generated by OpenCVE AI on September 20, 2026 at 22:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update all Apple operating system versions to the latest released releases (iOS 26.7/27 or newer, iPadOS 26.7/27 or newer, macOS Golden Gate 27 or newer, macOS Tahoe 26.7 or newer, tvOS 27, visionOS 27, watchOS 27).
  • If an upgrade cannot be performed immediately, restrict the installation or execution of non‑Apple‑signed applications to prevent exploitation of the flaw.
  • Monitor device logs for unexpected application crashes and apply subsequent security updates as they become available via System Settings.

Generated by OpenCVE AI on September 20, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Apple OS Crash Vulnerability Allowing Untrusted Apps to Cause System Termination

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-248
CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Malicious App Could Crash Apple Devices
Weaknesses CWE-665
CWE-758

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Malicious App Could Crash Apple Devices
Weaknesses CWE-665
CWE-758

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T13:32:00.061Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65410

cve-icon Vulnrichment

Updated: 2026-09-16T13:31:08.192Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:24.637

Modified: 2026-09-16T15:25:43.707

Link: CVE-2026-65410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-248

    Uncaught Exception

  • CWE-400

    Uncontrolled Resource Consumption