Junglewise Threat Intelligence

CVE-2026-65409: Apple iOS, iPadOS, and macOS type confusion in memory handling

CVE-2026-65409 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

A type confusion vulnerability affects multiple Apple operating systems, allowing an app to cause denial of service on affected devices. The issue impacts iPhones, iPads, and Mac computers, potentially disrupting user operations. Apple has released patches across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to address this memory handling issue.

Technical details

A type confusion issue in Apple's core operating system kernel memory handling was addressed through improved memory handling and input validation. The vulnerability allows an app with local execution context to cause unexpected process termination (denial of service). The attack requires no network access or user interaction beyond launching a malicious app; however, it is limited to causing DoS rather than privilege escalation or data exfiltration. Patches are available in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27, released on September 14, 2026.

Affected products

  • Apple iOS before 26.7, before 27
  • Apple iPadOS before 26.7, before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27

References

Related threats