CVE-2026-65415
massKernel Race Condition in Apple iOS, macOS, watchOS Enables Memory Read and Crashes
CVE-2026-65415 is a race condition (CWE-362) in Apple's kernel that was fixed with additional validation across all major Apple operating systems. The flaw allows a local user — or, per the CVSS vector, a remote attacker combined with user interaction such as opening crafted content — to cause unexpected system termination or read kernel memory. Reading kernel memory can expose sensitive data such as pointers and credentials that would aid further privilege-escalation or sandbox-escape attacks, while the termination vector provides denial of service. All devices running iOS, iPadOS, macOS, tvOS, visionOS, or watchOS versions prior to 27 are affected, which spans essentially the entire Apple hardware ecosystem. No public proof of concept exists, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Patch to iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, or watchOS 27 as soon as releases are available, prioritizing shared/kiosk devices and those running untrusted apps. Use MDM or automated update policies to force OS upgrades fleet-wide, and check that supervised devices are not deferring major-version updates. Because a local attack path exists, restrict sideloading and unvetted software on managed devices and watch for recurring unexpected system terminations that may indicate probing.
| Apple iOS | versions prior to iOS 27 |
| Apple iPadOS | versions prior to iPadOS 27 |
| Apple macOS (Golden Gate) | versions prior to macOS Golden Gate 27 |
| Apple tvOS | versions prior to tvOS 27 |
| Apple visionOS | versions prior to visionOS 27 |
| Apple watchOS | versions prior to watchOS 27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.