CVE-2026-65364
massOut-of-Bounds Read in Apple macOS Allows Remote Attackers to Crash Systems
Apple fixed an out-of-bounds read (CWE-125) in macOS, addressed with improved bounds checking. A remote attacker requiring no privileges, no user interaction, and low attack complexity could trigger the flaw and cause unexpected system termination, i.e., a full system crash or kernel panic. The CVSS 3.1 score is 7.5 (high) with availability-only impact (C:N/I:N/A:H), so the practical risk is remote denial of service rather than data theft or code execution. All Macs running macOS versions older than Sequoia 15.8, Tahoe 26.7, or Golden Gate 27 are affected. No public proof of concept is known, the flaw is not on CISA's KEV list, and there are no reports of exploitation in the wild.
What to do: Upgrade to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later) via System Settings > General > Software Update as soon as possible. Because the attack is remote, unauthenticated, and requires no user interaction, prioritize internet- or network-exposed Macs and Mac-based servers or kiosks where an unexpected crash would disrupt operations. No patch-alternative workaround is documented, so patching is the only reliable mitigation; verify deployments report the fixed build versions in MDM.
| Apple macOS Sequoia | before 15.8 |
| Apple macOS Tahoe | before 26.7 |
| Apple macOS Golden Gate | before 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination.
- Vendors
- apple
- Products
- macos
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.