PT-2026-53696 · Apple · Ios+3

·

CVE-2026-39868

·

Published

2026-05-13

·

Updated

2026-09-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions iOS versions prior to 26.5.2 iPadOS versions prior to 26.5.2 macOS Tahoe versions prior to 26.5.2
Description Improper input validation in the operating system kernel allows a malicious app to pass crafted data into a privileged system or kernel-facing interface. This can lead to kernel memory corruption, where the system's core memory is modified in an unintended way, or unexpected system termination. An attacker can exploit this by running a specially crafted app locally on a device to trigger the vulnerable code path and feed malformed inputs into the kernel, potentially resulting in a denial of service through forced reboots or privilege escalation.
Recommendations Update iOS to version 26.5.2. Update iPadOS to version 26.5.2. Update macOS Tahoe to version 26.5.2.

Exploit

Fix

LPE

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06810
CVE-2026-39868

Affected Products

Apple Macos
Ios
Ipados
Macos Tahoe