Description
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch OS
AI Analysis

Impact

A type confusion flaw allowing an application to cause an unexpected system termination was identified in Apple operating systems. The vulnerability results from an object being misidentified as another type, leading to unsafe handling and a crash of the operating system. The crash stops the system from operating normally and can cause loss of device functionality.

Affected Systems

The flaw affects Apple’s mobile and desktop operating systems: iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Any device running one of these affected versions is susceptible to the crash triggered by a malicious application.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog and no public exploitation is known. The CVSS score of 5.5 indicates moderate severity. Based on the description, it is inferred that the attack vector is local, with the flaw exploitable by a malicious application running on the device. Once exploited, the vulnerability results in a denial of service by terminating the operating system and may expose the device to additional instability if the crash occurs during critical operations.

Generated by OpenCVE AI on September 20, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to the latest OS release that includes the fix: iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27. Avoid sideloaded or custom packages that could exploit type confusion.
  • Deploy an MDM solution or system policies to restrict the privileges of third‑party applications and monitor for abnormal crash or system termination events.
  • Enable detailed crash reporting and monitor system logs for abnormal termination events to facilitate early detection and response to potential exploitation.

Generated by OpenCVE AI on September 20, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Type Confusion Leading to Unexpected System Termination in Apple Operating Systems

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Type confusion leads to system crash in Apple OS
Weaknesses CWE-374

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Type confusion leads to system crash in Apple OS
Weaknesses CWE-374

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:37:51.186Z

Reserved: 2026-09-01T21:13:17.759Z

Link: CVE-2026-84602

cve-icon Vulnrichment

Updated: 2026-09-17T15:37:42.553Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:35.710

Modified: 2026-09-18T14:38:38.607

Link: CVE-2026-84602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:00:05Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')