Out-of-Bounds Read Vulnerability in Apple iOS and macOS Products
CVE-2026-65349

6.6MEDIUM

Key Information:

Vendor

Apple

Vendor
CVE Published:
17 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-65349?

An out-of-bounds read vulnerability has been identified in Apple's iOS, iPadOS, and macOS products, which could allow an application to access unintended areas of memory. This may lead to unexpected application termination or unauthorized reading of kernel memory. Enhanced input validation measures have been implemented to address this threat in the respective software updates.

Affected Version(s)

iOS and iPadOS 0 < 26.6.1

macOS 0 < 15.8

macOS 0 < 26.6.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.