Junglewise Threat Intelligence

CVE-2026-65367: Apple iOS null pointer dereference in system services

CVE-2026-65367 · Severity: medium · CVSS 5.5 · Published 2026-08-25

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

iOS and iPadOS contain a null pointer dereference vulnerability in core system services that can be triggered by a malicious application. Exploitation allows an attacker to crash the operating system unexpectedly, causing service disruption and potentially data loss for affected users.

Technical details

A null pointer dereference vulnerability was identified in iOS and iPadOS system services that is triggered through insufficient input validation. The vulnerability is reachable from unprivileged applications without special privileges or user interaction. An attacker can craft a malicious input that bypasses validation checks, causing the system to dereference a null pointer and crash the affected process or potentially the entire device. The vulnerability was addressed through improved input validation logic in the affected code paths. Patches are available in iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, and iPadOS 26.5.

Affected products

  • Apple iOS before 18.7.9 and before 26.5
  • Apple iPadOS before 18.7.9 and before 26.5

Timeline

  • 2026-08-25: disclosed: CVE-2026-65367 publicly disclosed
  • 2026-05-11: patched: iOS 18.7.9, iPadOS 18.7.9, iOS 26.5, and iPadOS 26.5 released

References

Related threats