Junglewise Threat Intelligence

CVE-2026-65395: Apple Accelerate Framework out-of-bounds write

CVE-2026-65395 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple Visionos, Apple iPadOS, Apple macOS Tahoe, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Apple's Accelerate Framework is a system library used across Apple devices and Macs to process images and perform computationally intensive operations. A maliciously crafted image file can trigger an out-of-bounds write vulnerability that corrupts memory and causes the application to crash unexpectedly. This vulnerability affects iPhones, iPads, and Mac computers running the vulnerable software.

Technical details

An out-of-bounds write vulnerability exists in Apple's Accelerate Framework's image processing routines due to insufficient bounds checking. The vulnerability is triggered when processing a specially crafted image file, allowing an attacker to write data beyond the allocated buffer. This issue requires user interaction (opening or processing a malicious image) and can lead to unexpected process termination, potential information disclosure, or denial of service. The vulnerability has been fixed with improved bounds checking in iOS 27, iPadOS 27, macOS Golden Gate 27, and other affected OS releases patched on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched

References

Related threats