Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds write flaw, classified as CWE-787, exists in several Apple operating systems and allows an attacker to write beyond a buffer’s boundaries. The vulnerability can be triggered by a specially crafted input to the vulnerable component and may lead either to unexpected application termination or, in the worst case, to the execution of arbitrary code with the privileges of the affected process.

Affected Systems

Apple iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27 are all affected. Devices running any of these OS releases are vulnerable until updated to the patched versions.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is less than 1%, which implies a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed. The likely attack vector is remote; an attacker must deliver a crafted payload to the vulnerable component, after which the flaw can cause a crash or allow code execution.

Generated by OpenCVE AI on September 20, 2026 at 20:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to the latest releases that address the out-of-bounds write (iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27).
  • If a device cannot receive the required update, retire it or reassign it to a non-critical role.
  • Continuously monitor system logs, crash reports, and security events for signs of exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Vulnerability in Apple Operating Systems

Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Vulnerability in Apple Operating Systems Enabling Remote Code Execution

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Vulnerability in Apple Operating Systems Enabling Remote Code Execution

Tue, 15 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:55:38.445Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65414

cve-icon Vulnrichment

Updated: 2026-09-14T23:02:22.729Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:25.057

Modified: 2026-09-16T01:08:46.160

Link: CVE-2026-65414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:15:04Z

Weaknesses