• PATCH AVAILABLE

CVE-2026-65414: pre-auth remote code execution in Apple iOS and iPadOS

A remote attacker can cause app crashes or execute arbitrary code on Apple iOS and iPadOS devices via an out-of-bounds write (CVE-2026-65414). Affected releases include iOS and iPadOS 26.x before 26.7 and 27.x before 27; related Apple platforms listed below are also affected. The CVSS vector indicates no privileges and no user interaction are required to exploit this flaw, allowing unauthenticated attackers to target vulnerable devices.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01078
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply vendor updates promptly because this flaw requires no privileges or user interaction (CVSS shows PR:N and UI:N), making exposed devices high risk until patched.

What is CVE-2026-65414?

A remote attacker can cause app crashes or execute arbitrary code on Apple iOS and iPadOS devices via an out-of-bounds write (CVE-2026-65414). Affected releases include iOS and iPadOS 26.x before 26.7 and 27.x before 27; related Apple platforms listed below are also affected. The CVSS vector indicates no privileges and no user interaction are required to exploit this flaw, allowing unauthenticated attackers to target vulnerable devices. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.726.7
iOS and iPadOS 27.xbefore 2727
macOS 15.xbefore 15.815.8
macOS 26.xbefore 26.726.7
macOS 27.xbefore 2727
tvOS 27.xbefore 2727
visionOS 27.xbefore 2727
watchOS 27.xbefore 2727

Is CVE-2026-65414 being exploited?

There are no public reports of exploitation as of 2026-09-29 and no public exploit code is known.

How to fix CVE-2026-65414

  1. Upgrade affected devices to the fixed releases: iOS/iPadOS 26.7 or 27, macOS 15.8, macOS 26.7 or 27, tvOS 27, visionOS 27, and watchOS 27.
  2. Apply the vendor's security updates as soon as possible on all managed endpoints and block installation delays.
  3. Limit network exposure of vulnerable devices until patches are deployed and monitor for anomalous crashes or suspicious activity.
  4. Follow Apple’s guidance and deploy vendor-provided mitigations or configuration recommendations where applicable.

Frequently asked questions

Is CVE-2026-65414 being actively exploited?

No public reports indicate active exploitation as of 2026-09-29; CISA has not added this CVE to its Known Exploited Vulnerabilities catalog.

Which iOS and iPadOS versions are affected by CVE-2026-65414?

iOS and iPadOS 26.x before 26.7 and 27.x before 27 are listed as affected; related Apple platforms in the facts are similarly versioned and affected.

Is there a patch for CVE-2026-65414?

Yes; Apple issued fixes: iOS/iPadOS 26.7 and 27, macOS 15.8 and the listed macOS, tvOS, visionOS, and watchOS releases noted as fixed.

Does CVE-2026-65414 require authentication?

No; the CVSS vector indicates exploitation does not require privileges or user interaction, so authentication is not required.

References