AppleCVE-2026-65343
Apple iOS and iPadOS: use after free
High7.5CVE-2026-65343 · Published Aug 17, 2026 · updated Sep 14, 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iOS and iPadOS Product | < 26.6.1 | 26.6.1 |
| macOS Product | < 26.6.2 | 26.6.2 |
| tvOS Product | < 27 | 27 |
| visionOS Product | < 27 | 27 |
| watchOS Product | < 27 | 27 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-416
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Apple Safari: memory corruption | Medium5.4 | 26.6.1+3 more |
| Aug 17 | Apple iOS and iPadOS: integer overflow | High8.8 | 26.6.1+3 more |
| Aug 17 | Apple iOS and iPadOS: denial of service | Medium6.5 | 26.6.1+2 more |
| Aug 17 | Apple iOS and iPadOS: out-of-bounds read | Medium6.6 | 26.6.1+3 more |
| Aug 17 | Apple Safari: unhandled exceptional condition | Medium4.3 | 26.6.1+3 more |
| Aug 17 | Apple Safari: unhandled exceptional condition | Medium4.3 | 26.6.1+3 more |