Executive brief
The Apple Neural Engine is a processor that accelerates machine learning tasks on Apple devices. An integer overflow vulnerability in this component can cause applications to unexpectedly crash, disrupting user experience and potentially affecting critical device functionality. The issue has been patched in iOS 27, iPadOS 27, and corresponding macOS versions.
Technical details
CVE-2026-65408 is an integer overflow vulnerability in the Apple Neural Engine component affecting iOS, iPadOS, and macOS platforms. The vulnerability exists in input validation logic and can be triggered by a malicious app on the affected device. An attacker can cause unexpected system termination (denial of service) by crafting inputs that trigger the integer overflow condition. The flaw was addressed through improved input validation in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.
Affected products
- Apple iOS 26.7, 27, and later
- Apple iPadOS 26.7, 27, and later
- Apple macOS Golden Gate 27 and later
- Apple macOS Sequoia 15.8 and later
- Apple macOS Tahoe 26.7 and later
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched