Junglewise Threat Intelligence

CVE-2026-65359: Apple iOS out-of-bounds read in kernel memory

CVE-2026-65359 · Severity: high · CVSS 7.1 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A flaw in Apple's mobile and desktop operating systems allows a local user to read kernel memory—the core of the operating system—or cause the system to crash unexpectedly. An attacker with access to a device could exploit this to extract sensitive system data or disable functionality. The issue affects iPhones, iPads, Macs, Apple Watches, and related devices.

Technical details

This is an out-of-bounds read vulnerability in Apple's OS kernel memory access logic, addressed through improved bounds checking. The flaw allows a local, unprivileged user to read memory regions outside intended boundaries, potentially exposing kernel structures and sensitive data. Attack vector is local; no network access or authentication is required, but the attacker must have local execution capability on the device. Exploitation can result in unauthorized disclosure of kernel memory or denial of service (system termination). Apple patched this in iOS 26.7, iOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65359 published; security updates released
  • 2026-09-14: patched: iOS 26.7, iOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27 released

References

Related threats