Junglewise Threat Intelligence

CVE-2026-86903: Apple iOS out-of-bounds read in kernel memory

CVE-2026-86903 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Executive brief

iOS, iPadOS, and related Apple operating systems contain a vulnerability that allows malicious apps or crafted content to read sensitive kernel memory, which is the lowest-level operating system code that manages hardware and system security. An attacker exploiting this flaw could disclose confidential system information or secrets used by the operating system, potentially enabling further attacks on device security.

Technical details

An out-of-bounds read vulnerability exists in Apple's kernel that was addressed through improved input validation. The vulnerability allows an app to read memory beyond the bounds of an allocated buffer, potentially exposing kernel memory contents. The attack requires an app to be installed and executed on the device or for the user to process maliciously crafted input. The impact is information disclosure—an attacker can leak kernel memory which may contain sensitive system state or credentials. The issue is fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27 released on September 14, 2026.

Affected products

  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS before Golden Gate 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27

References

Related threats