Description
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content may lead to a denial-of-service.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A null pointer dereference occurs when Apple devices process web content. The flaw allows an attacker to trigger the dereference, forcing the operating system to terminate and restart. As a result, the device experiences a denial‑of‑service that disrupts normal operation. This weakness is classified as CWE‑476.

Affected Systems

Multiple Apple platforms are affected. The defect is present in iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27. All devices running these releases or earlier are susceptible until a later update is installed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability can be triggered simply by processing arbitrary web content, so any device that renders such content could be targeted. Although the issue is not listed in CISA’s KEV catalog, the denial‑of‑service impact remains significant for end‑users and services that rely on continuous device availability.

Generated by OpenCVE AI on September 20, 2026 at 18:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update iOS, iPadOS, watchOS, macOS, and visionOS to the latest releases that include the fix (e.g., iOS 26.7/27, iPadOS 26.7/27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27).
  • If a device cannot be updated immediately, remove it from networks where it may receive untrusted web content or disable WebKit‑based browsing until the patch is applied.
  • Configure device restrictions or apply configuration profiles to disable the affected web‑rendering features until the operating system is patched.

Generated by OpenCVE AI on September 20, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Apple Null Pointer Dereference Leads to Denial of Service in Web Rendering

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leading to Denial of Service in Apple iOS, iPadOS, macOS, visionOS, and watchOS

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leading to Denial of Service in Apple iOS, iPadOS, macOS, visionOS, and watchOS
Weaknesses CWE-476

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content may lead to a denial-of-service.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T18:27:36.120Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65412

cve-icon Vulnrichment

Updated: 2026-09-15T18:27:32.410Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:24.840

Modified: 2026-09-16T14:48:49.107

Link: CVE-2026-65412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:45:02Z

Weaknesses