Executive brief
The Apple Neural Engine, a machine learning accelerator in Apple's processors, contains an integer overflow vulnerability that could allow applications to cause system crashes or denial of service. An attacker would need to run a malicious app on the affected Mac to exploit this issue, potentially disrupting normal operations.
Technical details
CVE-2026-65413 is an integer overflow vulnerability in the Apple Neural Engine component affecting macOS. The issue was resolved through improved input validation to prevent overflow conditions. The vulnerability requires local code execution (user-level app execution on the target Mac) and can result in unexpected process termination or denial of service. The patch is available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. No evidence of active exploitation in the wild has been reported.
Affected products
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
Timeline
- 2026-09-14: disclosed: CVE-2026-65413 disclosed; patches released for macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7