VDB
CVE-2026-65367
CVE-2026-65367
PUBLISHED
CVSS 5.5 MEDIUM
Reported by apple · Published August 25, 2026
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | iOS and iPadOS | 0, 0 |
| Apple | iOS and iPadOS | 0, 0 |
Timeline
- Aug 25, 2026 CVE Published
- Aug 26, 2026 EPSS Score
- Aug 26, 2026 Coalition ESS Score
- Aug 27, 2026 Security Advisory
- Aug 27, 2026 CVE Updated
- Aug 28, 2026 EPSS Score
- Sep 24, 2026 EPSS Score