ZeroHour

CVE-2026-65410

mass

App-Triggered Denial of Service in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS

CVSS
EPSS
Published
()
Modified
AI analysis

This is a denial-of-service flaw spanning Apple's operating systems: a locally installed app may be able to cause unexpected system termination (a device crash or forced reboot), which Apple addressed by adding improved validation checks. It is triggered by running a malicious or misbehaving app on the device, which abuses the missing checks to bring down the OS; there is no indication of remote triggering, code execution, or data exposure. The impact an attacker gains is purely availability — the ability to crash or repeatedly terminate a victim's device. Affected users include those on iPhone, iPad, Mac, Apple TV, Apple Watch, and Apple Vision Pro devices running OS builds older than the fix releases (iOS/iPadOS 26.7 and 27, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27). There is no public PoC, the CVE is absent from CISA's KEV catalog, and no exploitation in the wild is known; the patch shipped amid a record-setting batch of Apple security fixes.

What to do: Deploy the fixed builds across the fleet: iOS/iPadOS 26.7 or 27, macOS Tahoe 26.7 or macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27; enabling automatic updates will cover most consumer and BYOD devices. Because exploitation requires a malicious app already present on the device, this is lower urgency than remotely exploitable bugs — standard controls such as App Store-only installation and MDM app allow-listing substantially limit the attack path. Monitor for the pending CVSS score and any crash-report patterns suggesting abuse of the termination path.

Affected
Apple iOSversions prior to iOS 26.7 and iOS 27 (fix releases)
Apple iPadOSversions prior to iPadOS 26.7 and iPadOS 27 (fix releases)
Apple macOS Tahoeversions prior to macOS Tahoe 26.7 (fix release)
Apple macOS Golden Gateversions prior to macOS Golden Gate 27 (fix release)
Apple tvOSversions prior to tvOS 27 (fix release)
Apple visionOSversions prior to visionOS 27 (fix release)
Apple watchOSversions prior to watchOS 27 (fix release)
Estimated exposure
mass≈1-2 billion active Apple devices (essentially the entire pre-update iPhone, iPad, Mac, Apple TV, Apple Watch, and Vision Pro install base) — Apple has publicly cited roughly 2 billion active devices worldwide, and because this flaw spans every major Apple OS prior to the listed fix releases, nearly all of that base was potentially exposed until patched — though actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

In the news

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.