AppleCVE-2026-65367
Apple iOS and iPadOS: null pointer dereference
Medium5.5CVE-2026-65367 · Published Aug 25, 2026 · updated Aug 27, 2026
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iOS and iPadOS Product | < 18.7.9 | 18.7.9 |
| < 26.5 | 26.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-476
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 30 | ## Impact An attacker who can choose a container or exec id may be able to... | High | 0.41.0 |
| Aug 25 | Apple iOS and iPadOS: buffer overflow | Medium5.5 | 26.6+2 more |
| Aug 25 | Apple iOS and iPadOS: improper privilege management | Low3.3 | 26.5 |
| Aug 25 | Apple Safari: protection mechanism failure | High8.8 | 26.5+2 more |
| Aug 21 | Apple watchOS: improper access control | Low2.4 | 26.4 |
| Aug 21 | Apple macOS: out-of-bounds read | Medium4.3 | 14.8.5+2 more |