Junglewise Threat Intelligence

CVE-2026-65402: Apple iOS and iPadOS use-after-free in AppleKeyStore

CVE-2026-65402 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple iPadOS. Vendors: Apple.

Executive brief

Apple's iOS and iPadOS operating systems contain a use-after-free memory vulnerability in the AppleKeyStore component, which manages cryptographic keys and security credentials. An installed app can trigger the vulnerability to crash the system unexpectedly, causing a denial of service. The vulnerability has been patched in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27.

Technical details

CVE-2026-65402 is a use-after-free vulnerability in Apple's AppleKeyStore framework, addressed through improved memory management. The vulnerability allows a locally installed app to trigger unexpected system termination by causing the operating system to access freed memory. Since AppleKeyStore manages sensitive cryptographic material, exploitation could potentially have broader implications beyond availability. No network attack vector is required—exploitation is limited to local apps already running on the device. Patches are available in iOS/iPadOS 26.7 and iOS/iPadOS 27.

Affected products

  • Apple iOS before 26.7 and 27
  • Apple iPadOS before 26.7 and 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65402 disclosed as part of iOS 27 and iPadOS 27 security release
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, iOS 27, and iPadOS 27

References

Related threats