Skip to content

CVE-2026-65415

8.1 HIGHEPSS 0.16%
  1. Published14 Sept 2026

Description

A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.

CVSS 3.1 breakdown

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Affected products

Apple Ipados< 27.0
Apple Iphone Os< 27.0
Apple Macos< 27.0
Apple Tvos< 27.0
Apple Visionos< 27.0
Apple Watchos< 27.0

Remediation

Fixed in
Apple Ipados27.0
Apple Iphone Os27.0
Apple Macos27.0
Apple Tvos27.0
Apple Visionos27.0
Apple Watchos27.0

References

Frequently asked

Is CVE-2026-65415 being actively exploited?

CVE-2026-65415 is not in the CISA KEV catalog. Its EPSS exploit probability is 0.16%.

How severe is CVE-2026-65415?

CVE-2026-65415 has a CVSS 3.1 base score of 8.1, rated high. EPSS estimates a 0.16% probability of exploitation.

Which products are affected by CVE-2026-65415?

Affected products include Apple Ipados, Apple Iphone Os, Apple Macos, Apple Tvos, Apple Visionos, and 1 more.

How do I fix CVE-2026-65415?

Upgrade affected software to a fixed version, for example Apple Ipados 27.0, Apple Iphone Os 27.0, Apple Macos 27.0 or later, then confirm no affected versions remain in your inventory.

How Secuno handles this

Secuno correlates vulnerabilities like CVE-2026-65415 against the real software inventory on every managed device, every day. Rather than a static severity, each match is scored in context: exploit availability, EPSS, the asset's exposure, and business criticality decide where it lands in the queue. If an affected version is present anywhere across your portfolio, it surfaces automatically with a prioritised remediation path.

Data from the NVD, CISA KEV catalog and FIRST EPSS. CVSS 3.1 base score shown where available.