Junglewise Threat Intelligence

CVE-2026-65405: Apple iOS and macOS memory initialization issue

CVE-2026-65405 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A memory initialization flaw in Apple's operating systems could allow an app to determine kernel memory layout, potentially exposing sensitive security information used by the operating system. The vulnerability affects iPhones, iPads, Macs, and other Apple devices, and was patched in iOS 27, macOS Golden Gate 27, and related OS updates released in September 2026.

Technical details

This is a memory initialization vulnerability affecting Apple's kernel. The issue allows an application to infer or determine kernel memory layout through information disclosure, potentially bypassing ASLR (Address Space Layout Randomization) protections. The attack requires no special privileges—a standard app can trigger the leak. The fix involves improved memory handling to prevent uninitialized memory from being accessible. Apple patched this in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27, all released on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65405 disclosed; patches released for iOS 27, iPadOS 27, macOS Golden Gate 27, and other Apple OS versions
  • 2026-09-14: patched: Patched in iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats