Junglewise Threat Intelligence

CVE-2026-65360: Apple iOS race condition in state handling

CVE-2026-65360 · Severity: medium · CVSS 4.7 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, and related operating systems contain a race condition vulnerability in state handling that can cause apps to terminate unexpectedly. An attacker could exploit this condition to crash applications, potentially disrupting user experience or creating a denial-of-service condition on affected devices.

Technical details

A race condition was identified in Apple's operating system state handling logic, allowing an app to trigger unexpected system termination. The vulnerability stems from improper synchronization of shared state during concurrent operations, enabling a local app to cause a denial of service. The issue affects multiple Apple platforms (iOS, iPadOS, macOS, tvOS, visionOS, watchOS) and has been addressed through improved state management. Exploitation requires a malicious or compromised app already running on the device (local attack vector), and no active exploitation in the wild has been reported.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27, Sequoia before 15.8, Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats