Description
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7. Connecting a malicious accessory may cause unexpected system termination.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability allows memory corruption when a malicious accessory connects to a device. Based on the description, it is inferred that the attack requires a physical or local connection of a specially crafted accessory, which can lead to system termination. This impact corresponds to a denial of service, as the operating system crashes and becomes unavailable until reboot.

Affected Systems

Apple devices running iOS 26.7 and 27, iPadOS 26.7 and 27, macOS Golden Gate 27 and macOS Tahoe 26.7 are affected. The issue is resolved in newer releases of each platform. The affected platforms include iPhones and iPads with iOS up to 27, iPads with iPadOS up to 27, and Macs with macOS up to 27. Current installations of these operating systems are vulnerable.

Risk and Exploitability

The exploit requires possession of a malicious accessory that can supply crafted input to the device. The EPSS score is < 1%, indicating a very low probability of exploitation in the wild, and the CVSS score of 5.5 reflects a medium severity denial‑of‑service effect. The vulnerability is not listed in the CISA KEV catalog. Although the attack vector is local/physical, the risk to a device in a managed environment is elevated if untrusted accessories are allowed. Until patching, the best mitigation is to avoid using unknown accessories.

Generated by OpenCVE AI on September 20, 2026 at 22:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the OS update that includes the fix, which strengthens input validation for accessory data, mitigating the memory corruption flaw (CWE‑20).
  • Until a patch is in place, restrict the use of unknown or third‑party accessories to prevent malformed data from triggering a crash.
  • Verify that any external accessories are Apple‑certified and adhere to strict input validation requirements before connecting them to a device.

Generated by OpenCVE AI on September 20, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption Causing System Termination via Malicious Accessory

Sun, 20 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malicious Accessory Memory Corruption on Apple Operating Systems
Weaknesses CWE-119

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malicious Accessory Memory Corruption on Apple Operating Systems
Weaknesses CWE-119
CWE-20

Tue, 15 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7. Connecting a malicious accessory may cause unexpected system termination.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T17:33:08.833Z

Reserved: 2026-09-08T16:43:41.878Z

Link: CVE-2026-86924

cve-icon Vulnrichment

Updated: 2026-09-16T17:33:03.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:41.863

Modified: 2026-09-18T13:04:43.600

Link: CVE-2026-86924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation