Junglewise Threat Intelligence

CVE-2026-65358: Apple iOS, iPadOS, macOS race condition in state handling

CVE-2026-65358 · Severity: medium · CVSS 4.7 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A race condition affecting Apple's mobile and desktop operating systems can cause unexpected application or system termination. An attacker exploiting this issue could trigger a denial of service that disrupts user workflow or device availability, though no data breach or privilege escalation is known to occur.

Technical details

A race condition was identified in state handling across multiple Apple operating systems. The vulnerability allows improper concurrent access to shared state, potentially leading to unexpected process or system termination. The attack vector and specific preconditions are not detailed in the advisory, but the widespread fix across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS suggests a core framework issue. No active exploitation in the wild has been reported. Patches are available in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats