An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

zetlyn/cve-nvd vulnerability cve CVE-2026-65408 cpe cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* known 2026-09-14

https://nvd.nist.gov/vuln/detail/CVE-2026-65408

Properties

cvss5.5
receipt
Source
NVD
Its words
5.5
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination."
      }
    ],
    "id": "CVE-2026-65408",
    "lastModified": "2026-09-17T18:40:17.750",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65408",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T15:58:15.518775Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:24.420",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
productiOS and iPadOS
receipt
Source
NVD
Its words
iOS and iPadOS
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCiOS and iPadOS
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination."
      }
    ],
    "id": "CVE-2026-65408",
    "lastModified": "2026-09-17T18:40:17.750",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65408",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T15:58:15.518775Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:24.420",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
statusAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination."
      }
    ],
    "id": "CVE-2026-65408",
    "lastModified": "2026-09-17T18:40:17.750",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65408",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T15:58:15.518775Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:24.420",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
vendorApple
receipt
Source
NVD
Its words
Apple
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCApple
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "iOS and iPadOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "macOS",
            "vendor": "Apple",
            "versions": [
              {
                "lessThan": "15.8",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "26.7",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              },
              {
                "lessThan": "27",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "product-security@apple.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0896A319-539F-45D2-ACA1-7225AE5C06ED",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "B331E4FC-727F-403B-8689-E647A51204FD",
                "versionEndExcluding": "26.7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "241A56D1-1E33-4317-A053-85AF8E3770B3",
                "versionEndExcluding": "15.8",
                "versionStartIncluding": "15.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1BE83000-26C0-49C5-A966-BB40AD6F8BEE",
                "versionEndExcluding": "26.7",
                "versionStartIncluding": "26.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination."
      }
    ],
    "id": "CVE-2026-65408",
    "lastModified": "2026-09-17T18:40:17.750",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-65408",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-17T15:58:15.518775Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-14T21:17:24.420",
    "references": [
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149034"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149035"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149041"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149042"
      },
      {
        "source": "product-security@apple.com",
        "tags": [
          "Vendor Advisory",
          "Release Notes"
        ],
        "url": "https://support.apple.com/en-us/149043"
      }
    ],
    "sourceIdentifier": "product-security@apple.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-190"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}

Text

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.