Junglewise Threat Intelligence

CVE-2026-65357: Apple iOS kernel memory corruption in memory handling

CVE-2026-65357 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Apple Tvos, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS, iPadOS, and related Apple operating systems contain a memory handling vulnerability that allows apps to write data into protected kernel memory or cause unexpected system crashes. Attackers can exploit this by running a malicious app on an affected device to destabilize the system, potentially leading to data corruption or denial of service.

Technical details

The vulnerability is a memory handling defect in iOS kernel code that permits an unprivileged application to write to kernel memory or trigger uncontrolled system termination. The issue was addressed through improved memory bounds checking and validation in affected OS versions. Attack requires the victim to install and run a malicious app; no network reachability or user interaction beyond installation is required. An attacker can achieve denial of service or potentially kernel memory corruption. The vulnerability is patched in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 released July 27, 2026.

Affected products

  • Apple iOS before 26.6
  • Apple iPadOS before 26.6
  • Apple macOS Tahoe before 26.6
  • Apple tvOS before 26.6
  • Apple visionOS before 26.6
  • Apple watchOS before 26.6

Timeline

  • 2026-09-14: disclosed
  • 2026-07-27: patched: Fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6

References

Related threats