Junglewise Threat Intelligence

CVE-2026-65412: Apple iOS and iPadOS null pointer dereference in web content processing

CVE-2026-65412 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Tahoe. Vendors: Apple.

Executive brief

iOS and iPadOS contain a null pointer dereference vulnerability in the web content rendering engine. An attacker who convinces a user to view a specially crafted webpage can crash the device, causing a denial-of-service. This affects iPhone and iPad users who browse the internet or view web content within apps.

Technical details

This vulnerability is a null pointer dereference in the web content processing pipeline of iOS and iPadOS. The root cause stems from insufficient input validation when handling web content, allowing a maliciously crafted webpage to trigger an unexpected dereference of a null pointer. The attack vector is network-based and requires user interaction (the user must visit or interact with the malicious webpage). An attacker can achieve a denial-of-service by crashing the affected application or process. The vulnerability has been addressed in iOS 27, iPadOS 27, and earlier release versions (iOS 26.7, iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, and watchOS 27) through improved input validation.

Affected products

  • Apple iOS before 26.7 and before 27
  • Apple iPadOS before 26.7 and before 27
  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65412 disclosed; security updates released for iOS 27, iPadOS 27, macOS Golden Gate 27, and other platforms
  • 2026-09-14: patched: Patches released in iOS 27/iPadOS 27, iOS 26.7/iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27

References

Related threats