Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65414 | Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Remote Code Execution Apple patched a critical out-of-bounds write (CWE-787) memory-corruption flaw spanning nearly its entire operating-system lineup: iOS, iPadOS, macOS (Sequoia, Tahoe, Golden Gate), tvOS, visionOS, and watchOS. A remote attacker could trigger the flaw with no privileges and no user interaction (CVSS 3.1: 9.8, network vector, low complexity), causing unexpected app termination or potentially arbitrary code execution on the affected device. The advisory does not identify the vulnerable component or exact trigger, so defenders should assume any affected system is remotely attackable until patched. All users running iOS/iPadOS before 26.7, macOS Sequoia before 15.8, macOS Tahoe before 26.7, or pre-release tvOS/visionOS/watchOS builds older than 27 are affected. No public proof of concept exists, no exploitation in the wild is known, and the flaw is not on CISA's KEV list; fixes shipped in the listed updates. Do: Update all Apple devices promptly: iPhones/iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, Apple TV to tvOS 27, Apple Watch to watchOS 27, and Vision Pro to visionOS 27. Enable automatic security updates and use MDM/inventory to find devices still on older OS trains. Given the 9.8 CVSS with no user interaction required, treat patching as high priority even though no exploitation has been observed. | 9.8 | — |
| masspotentially 1+ billion devices (Apple's ~2.35 billion active-device install base, most on affected OS trains) |