Executive brief
Apple's iOS and iPadOS operating systems contain a memory management flaw in the kernel that can be triggered remotely. An attacker can exploit this issue to cause devices to crash unexpectedly, disrupting business operations and user productivity. This affects iPhones and iPads running iOS 26.6.1 and earlier.
Technical details
CVE-2026-65343 is a use-after-free vulnerability in the iOS and iPadOS kernel. The flaw was introduced through improper memory management in kernel code, allowing an attacker to reference memory after it has been freed. A remote attacker can trigger this issue without requiring authentication or user interaction, causing unexpected system termination (denial of service). The vulnerability was patched in iOS 26.6.1 and iPadOS 26.6.1 through improved memory management. While the impact is primarily availability-focused, use-after-free bugs in kernel code can potentially be leveraged for privilege escalation or information disclosure with additional exploitation techniques.
Affected products
- Apple iOS before 26.6.1
- Apple iPadOS before 26.6.1
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: iOS 26.6.1 and iPadOS 26.6.1 released