Skip to content
AppleCVE-2026-65367

Apple iOS and iPadOS: null pointer dereference

Medium5.5CVE-2026-65367 · Published Aug 25, 2026 · updated Aug 27, 2026

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.

Apple advisory

Affected versions

PackageAffectedFixed in
iOS and iPadOS
Product
< 18.7.918.7.9
< 26.526.5
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-476

More Apple advisories

All Apple
Advisory
## Impact An attacker who can choose a container or exec id may be able to...
HighAug 30
Apple iOS and iPadOS: buffer overflow
Medium5.5Aug 25
Apple iOS and iPadOS: improper privilege management
Low3.3Aug 25
Apple Safari: protection mechanism failure
High8.8Aug 25
Apple watchOS: improper access control
Low2.4Aug 21
Apple macOS: out-of-bounds read
Medium4.3Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.