Description
A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: System Crash and Information Disclosure
Action: Apply OS Update
AI Analysis

Impact

A race condition in a core kernel component allows a local user to trigger an unexpected system termination or read kernel memory. The vulnerability is rooted in improper synchronization (CWE-362). Consequently, a local attacker or an authenticated user could cause application or system crashes and gain visibility of privileged information, which may aid in further exploitation. Based on the description, it is inferred that the defect requires local privilege and does not provide a remote attack vector.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and to 27 on each platform contain the race condition; iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 include the additional validation that fixes the issue.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, but its EPSS score is less than 1 %, indicating a very low likelihood of exploitation under current threat conditions. It is not listed in the CISA KEV catalog. Risk is confined to individuals with local access, and the impact ranges from system instability to potential disclosure of kernel memory. While the flaw does not appear to support remote exploitation, a local attacker could indirectly leverage the situation for privilege escalation if kernel data is useful.

Generated by OpenCVE AI on September 20, 2026 at 18:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest OS update that includes iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, or watchOS 27.
  • Reduce the local attack surface by limiting user privileges and disabling non‑essential kernel extensions that may interact with the race condition.
  • Monitor device stability for unexpected crashes or abnormal kernel activity and report findings to Apple for further investigation.

Generated by OpenCVE AI on September 20, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title iOS 27 and Related OSes Race Condition: System Crash and Kernel Memory Disclosure

Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Local User to Cause System Termination or Read Kernel Memory
Weaknesses CWE-200

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Local User to Cause System Termination or Read Kernel Memory
Weaknesses CWE-200
CWE-362

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-15T15:12:53.547Z

Reserved: 2026-07-22T00:47:18.621Z

Link: CVE-2026-65415

cve-icon Vulnrichment

Updated: 2026-09-15T15:12:42.627Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:25.163

Modified: 2026-09-16T01:08:38.200

Link: CVE-2026-65415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:00:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')