Apple · Ios · CVE-2026-39868
**Name of the Vulnerable Software and Affected Versions**
iOS versions prior to 26.5.2
iPadOS versions prior to 26.5.2
macOS Tahoe versions prior to 26.5.2
**Description**
Improper input validation in the operating system kernel allows a malicious app to pass crafted data into a privileged system or kernel-facing interface. This can lead to kernel memory corruption, where the system's core memory is modified in an unintended way, or unexpected system termination. An attacker can exploit this by running a specially crafted app locally on a device to trigger the vulnerable code path and feed malformed inputs into the kernel, potentially resulting in a denial of service through forced reboots or privilege escalation.
**Recommendations**
Update iOS to version 26.5.2.
Update iPadOS to version 26.5.2.
Update macOS Tahoe to version 26.5.2.