
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65343 is a use-after-free vulnerability in the kernel component of Apple iOS, iPadOS, and macOS Tahoe that allows a remote attacker to cause unexpected system termination. It was disclosed and patched on August 17, 2026, affecting iOS and iPadOS versions prior to 26.6.1 and macOS Tahoe versions prior to 26.6.2. The vulnerability was discovered by Drinor Selmanaj (Sentry) and Surya Narayan Kushwaha (Apple macOS Advisory, Apple iOS Advisory). The CVSS category is estimated as HIGH, though a formal CVSS score has not yet been published (Feedly).
The vulnerability is classified as a use-after-free (CWE-416) in the Apple kernel, arising from improper memory management where a memory object is accessed after it has been freed. Apple addressed the issue with improved memory management in the patched releases (Apple macOS Advisory, Apple iOS Advisory). The attack vector is network-based and does not require authentication or user interaction, as a remote attacker can trigger the condition to cause unexpected system termination. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Feedly).
Successful exploitation results in a denial-of-service condition, specifically unexpected system termination (kernel crash) on affected Apple devices. The impact is limited to availability — confidentiality and integrity are not directly affected based on current vendor descriptions. Affected devices span a wide range of Apple hardware including iPhone 11 and later, multiple iPad generations, and Macs running macOS Tahoe (Apple iOS Advisory, Apple macOS Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the disclosure date (Feedly). The EPSS score is reported as 0.0, indicating a currently low probability of exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Apple has released patches addressing this vulnerability. Users should update to iOS 26.6.1, iPadOS 26.6.1, or macOS Tahoe 26.6.2 as appropriate for their device (Apple iOS Advisory, Apple macOS Advisory). No configuration-based workarounds have been published; upgrading to the patched version is the only recommended remediation. Given the remote exploitability and denial-of-service potential, patching should be prioritized for internet-facing or critical Apple devices.
The SANS Internet Storm Center published a diary entry referencing this vulnerability shortly after disclosure (SANS ISC). CyberKendra covered the broader Apple patch release, noting that Apple patched 122 flaws including this macOS kernel issue (CyberKendra). The vulnerability was also listed in the Full Disclosure mailing list (Seclists). Community reaction has been measured, consistent with a denial-of-service vulnerability lacking active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."