Executive brief
A race condition in Apple operating systems allows a local attacker to cause unexpected system crashes or read sensitive kernel memory. This can lead to system instability or disclosure of protected system information that could be leveraged in further attacks.
Technical details
A race condition in Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, watchOS) allows local users to trigger a kernel vulnerability. The vulnerability was addressed through additional validation logic, mitigating the timing window that allows the race condition to occur. A local attacker with no special privileges can exploit this to cause unexpected system termination (denial of service) or read kernel memory, potentially exposing sensitive system information. The vulnerability is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.
Affected products
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS before Golden Gate 27
- Apple tvOS before 27
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-65415 publicly disclosed
- 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27