CVE-2026-39868
Description
This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
In plain language
AI Low urgencyThis is a bug in Apple iOS and macOS that could let an app crash the system or corrupt low-level memory; typical small businesses should update to the latest iOS 26.5.2 / iPadOS 26.5.2 / macOS Tahoe 26.5.2 when convenient.
Improved input validation in iOS/iPadOS and macOS Tahoe 26.5.2 fixes a flaw where a malformed input from an app could trigger unexpected system termination or kernel memory corruption (attack vector and reachability details not publicly specified).
What to do now
- Check which Apple devices you use (iPhone/iPad/Mac) and their current operating system versions.
- Update iPhone and iPad to iOS 26.5.2 and iPadOS 26.5.2.
- Update Macs to macOS Tahoe 26.5.2.
- After updating, verify devices are stable by running your normal apps and watching for unexpected restarts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Apple Patches iOS and macOS - SANS Internet Storm Centeren·SANS Internet Storm Center· Patch iOS mobile
- Apple Patches Everything (July 2026) - SANS ISCen·SANS Internet Storm Center· Patch macOS zero-day
- June 2026 Apple Updates - SANS Internet Storm Centeren·SANS Internet Storm Center· Patch iOS web-app
- Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugsen·The Hacker News· Patch iOS ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-39868 and every CVE in our database. Create a free account — no credit card required.
Create Free Account