• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65343: use-after-free denial of service in Apple iOS and iPadOS

A remote attacker can cause unexpected system termination on Apple iOS and iPadOS devices due to a use-after-free vulnerability tracked as CVE-2026-65343. The flaw affects iOS and iPadOS 26.x before 26.6.1; macOS Tahoe 26.x before 26.6.2; and tvOS, visionOS, and watchOS 27.x before their 27 releases. No privileges or user interaction are required for an attacker with network access to trigger the condition that leads to availability impact.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.5HIGH
EPSS
0.00686
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so update immediately to the listed fixed releases (26.6.1, 26.6.2, 27) or restrict network exposure to vulnerable devices until you can patch.

What is CVE-2026-65343?

A remote attacker can cause unexpected system termination on Apple iOS and iPadOS devices due to a use-after-free vulnerability tracked as CVE-2026-65343. The flaw affects iOS and iPadOS 26.x before 26.6.1; macOS Tahoe 26.x before 26.6.2; and tvOS, visionOS, and watchOS 27.x before their 27 releases. No privileges or user interaction are required for an attacker with network access to trigger the condition that leads to availability impact. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.6.126.6.1
macOS 26.xbefore 26.6.226.6.2
tvOS 27.xbefore 2727
visionOS 27.xbefore 2727
watchOS 27.xbefore 2727

Is CVE-2026-65343 being exploited?

Public exploit code is available.

How to fix CVE-2026-65343

  1. Install vendor fixes: update iOS/iPadOS to 26.6.1, macOS to 26.6.2, and tvOS/visionOS/watchOS to 27.
  2. If you cannot update immediately, reduce network exposure of vulnerable devices and services to untrusted networks.
  3. Monitor device stability and logs for unexpected crashes or reboots and apply vendor guidance.

Frequently asked questions

Is CVE-2026-65343 being actively exploited?

Public exploit code is available for CVE-2026-65343.

Which iOS and iPadOS versions are affected by CVE-2026-65343?

iOS and iPadOS 26.x before 26.6.1 are affected by CVE-2026-65343.

Is there a patch for CVE-2026-65343?

Yes, Apple fixed the issue in iOS and iPadOS 26.6.1 (and corresponding macOS, tvOS, visionOS, and watchOS releases).

Does CVE-2026-65343 require authentication?

No, CVE-2026-65343 does not require authentication or user interaction to be triggered.

References