Executive brief
Apple iOS and iPadOS manage core phone and tablet functionality, including system memory protection. A flaw in the kernel's memory handling could allow a malicious app to crash the device unexpectedly or corrupt protected system memory, potentially enabling further attacks or data compromise.
Technical details
CVE-2026-65330 is an out-of-bounds memory access vulnerability in the Apple kernel affecting iOS 26.6.1 and iPadOS 26.6.1. The vulnerability involves improved memory handling in the kernel component, allowing an app to cause unexpected system termination or corrupt kernel memory without requiring special privileges or user interaction beyond running the app. The flaw was addressed through improved memory handling; patches are available in iOS 26.6.1 and iPadOS 26.6.1 released on August 17, 2026.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched