Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (app crash)
Action: Update OS
AI Analysis

Impact

An out-of-bounds write occurs when the system processes a maliciously crafted image due to insufficient bounds checking. The flaw can trigger an unexpected termination of the receiving application, disrupting user experience and service availability. No evidence in the data indicates that the memory corruption can be leveraged for code execution or privilege escalation, so the primary consequence remains a denial of service.

Affected Systems

Apple iOS versions earlier than 26.7, iPadOS versions earlier than 26.7, and macOS Golden Gate releases prior to 27 are affected. The issue is fixed in iOS 26.7, iPadOS 26.7, and macOS Golden Gate 27.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known active exploitation. The likely attack vector is the delivery of a malicious image to a vulnerable application, which may cause the application to crash.

Generated by OpenCVE AI on September 20, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iOS to version 26.7 or later
  • Upgrade iPadOS to version 26.7 or later
  • Upgrade macOS to Golden Gate 27 or later

Generated by OpenCVE AI on September 20, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causing App Crashes in iOS, iPadOS, and macOS

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Apple iOS/macOS Out‑of‑Bounds Write in Image Processing Causing App Crashes
Weaknesses CWE-787

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Apple iOS/macOS Out‑of‑Bounds Write in Image Processing Causing App Crashes
Weaknesses CWE-787

Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:49:28.295Z

Reserved: 2026-09-08T16:43:41.870Z

Link: CVE-2026-86869

cve-icon Vulnrichment

Updated: 2026-09-17T15:49:08.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:38.480

Modified: 2026-09-18T17:32:29.070

Link: CVE-2026-86869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:30:05Z

Weaknesses