Junglewise Threat Intelligence

CVE-2026-65413: Apple macOS integer overflow in Apple Neural Engine

CVE-2026-65413 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

The Apple Neural Engine, a machine learning accelerator in Apple's processors, contains an integer overflow vulnerability that could allow applications to cause system crashes or denial of service. An attacker would need to run a malicious app on the affected Mac to exploit this issue, potentially disrupting normal operations.

Technical details

CVE-2026-65413 is an integer overflow vulnerability in the Apple Neural Engine component affecting macOS. The issue was resolved through improved input validation to prevent overflow conditions. The vulnerability requires local code execution (user-level app execution on the target Mac) and can result in unexpected process termination or denial of service. The patch is available in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. No evidence of active exploitation in the wild has been reported.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: CVE-2026-65413 disclosed; patches released for macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7

References

Related threats