ZeroHour

CVE-2026-65414

mass

Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Remote Code Execution

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Apple patched a critical out-of-bounds write (CWE-787) memory-corruption flaw spanning nearly its entire operating-system lineup: iOS, iPadOS, macOS (Sequoia, Tahoe, Golden Gate), tvOS, visionOS, and watchOS. A remote attacker could trigger the flaw with no privileges and no user interaction (CVSS 3.1: 9.8, network vector, low complexity), causing unexpected app termination or potentially arbitrary code execution on the affected device. The advisory does not identify the vulnerable component or exact trigger, so defenders should assume any affected system is remotely attackable until patched. All users running iOS/iPadOS before 26.7, macOS Sequoia before 15.8, macOS Tahoe before 26.7, or pre-release tvOS/visionOS/watchOS builds older than 27 are affected. No public proof of concept exists, no exploitation in the wild is known, and the flaw is not on CISA's KEV list; fixes shipped in the listed updates.

What to do: Update all Apple devices promptly: iPhones/iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, Apple TV to tvOS 27, Apple Watch to watchOS 27, and Vision Pro to visionOS 27. Enable automatic security updates and use MDM/inventory to find devices still on older OS trains. Given the 9.8 CVSS with no user interaction required, treat patching as high priority even though no exploitation has been observed.

Affected
Apple iOSPrior to iOS 26.7 (26.x and earlier trains); fixed in iOS 26.7 and iOS 27
Apple iPadOSPrior to iPadOS 26.7 (26.x and earlier trains); fixed in iPadOS 26.7 and iPadOS 27
Apple macOS SequoiaPrior to 15.8; fixed in 15.8
Apple macOS TahoePrior to 26.7; fixed in 26.7
Apple macOS Golden GatePrior to 27; fixed in 27
Apple tvOSPrior to 27; fixed in 27
Apple visionOSPrior to 27; fixed in 27
Apple watchOSPrior to 27; fixed in 27
Estimated exposure
masspotentially 1+ billion devices (Apple's ~2.35 billion active-device install base, most on affected OS trains) — Apple has publicly reported more than 2 billion active devices worldwide, and the affected platforms (iPhone, iPad, Mac, Apple TV, Apple Watch, Vision Pro) cover essentially all of them, so the unpatched population plausibly reaches…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.

Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.