Junglewise Threat Intelligence

CVE-2026-65377: Apple iOS and iPadOS memory corruption in Accelerate Framework

CVE-2026-65377 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

The Accelerate Framework, a core Apple library used by apps to process images and perform computational tasks, contains a memory corruption vulnerability that can be triggered by processing a maliciously crafted image. An attacker can crash apps or cause unexpected system termination; in some cases this could be leveraged for further exploitation. This affects iPhones, iPads, and related Apple devices.

Technical details

An out-of-bounds write issue in the Accelerate Framework is addressed with improved bounds checking. The vulnerability can be triggered by processing a maliciously crafted image, leading to unexpected process termination. The attack vector is local (requires an app to process attacker-controlled image data), and the impact ranges from denial of service (app crash) to potential code execution depending on memory layout and exploit sophistication. Apple has patched this in iOS 27 and iPadOS 27 (released 2026-09-14), as well as macOS Golden Gate 27 and other platforms.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: Patched in iOS 27, iPadOS 27, macOS Golden Gate 27, and other platforms

References

Related threats