CVE-2026-65398: An app may be able to cause unexpected system termination or corrupt kernel memory in Apple iOS and iPadOS
CVE-2026-65398 is an out-of-bounds access vulnerability in Apple iOS and iPadOS that could allow an app to cause unexpected system termination or corrupt kernel memory. This issue has been addressed with improved bounds checking and fixed in iOS 27 and iPadOS 27. Prior versions are affected. No known exploits are reported in the wild.
AI Analysis
Technical Summary
This vulnerability involves an out-of-bounds access flaw in Apple iOS and iPadOS that could be triggered by a malicious app to cause the system to terminate unexpectedly or to corrupt kernel memory. Apple fixed the issue by improving bounds checking in iOS 27 and iPadOS 27, as well as in other Apple operating systems like macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. The vulnerability affects all versions prior to 27.
Potential Impact
An attacker with the ability to run a malicious app on the affected devices could cause unexpected system termination or kernel memory corruption, potentially leading to system instability or denial of service. There is no indication of privilege escalation or arbitrary code execution from the provided data. No known exploits in the wild have been reported.
Mitigation Recommendations
Apply the official update to iOS 27 or later and iPadOS 27 or later, which contain the fix with improved bounds checking. Devices running earlier versions remain vulnerable until updated. No other mitigations are specified.
CVE-2026-65398: An app may be able to cause unexpected system termination or corrupt kernel memory in Apple iOS and iPadOS
Description
CVE-2026-65398 is an out-of-bounds access vulnerability in Apple iOS and iPadOS that could allow an app to cause unexpected system termination or corrupt kernel memory. This issue has been addressed with improved bounds checking and fixed in iOS 27 and iPadOS 27. Prior versions are affected. No known exploits are reported in the wild.
Affected software
Apple
iOS and iPadOS
Apple
macOS
Apple
tvOS
Apple
visionOS
Apple
watchOS
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an out-of-bounds access flaw in Apple iOS and iPadOS that could be triggered by a malicious app to cause the system to terminate unexpectedly or to corrupt kernel memory. Apple fixed the issue by improving bounds checking in iOS 27 and iPadOS 27, as well as in other Apple operating systems like macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. The vulnerability affects all versions prior to 27.
Potential Impact
An attacker with the ability to run a malicious app on the affected devices could cause unexpected system termination or kernel memory corruption, potentially leading to system instability or denial of service. There is no indication of privilege escalation or arbitrary code execution from the provided data. No known exploits in the wild have been reported.
Mitigation Recommendations
Apply the official update to iOS 27 or later and iPadOS 27 or later, which contain the fix with improved bounds checking. Devices running earlier versions remain vulnerable until updated. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apple
- Date Reserved
- 2026-07-22T00:46:56.740Z
- State
- PUBLISHED
Threat ID: 6aa860fd55bf5e2cf59d2580
Added to database: 09/14/2026, 21:02:53 UTC
Last enriched: 09/14/2026, 22:28:00 UTC
Last updated: 09/15/2026, 03:18:54 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.