CVE-2026-65353: Buffer Overflow
Accessibility. This issue was addressed through improved state management.
Other sources
Accounts Framework. This issue was addressed with improved data protection.
— Apple
Accounts. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Accounts. An access issue was addressed with additional sandbox restrictions.
— Apple
afpfs. A buffer overflow was addressed with improved bounds checking.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.6 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.6 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.6
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-64732
- CVE-2026-64733
- CVE-2026-43801
- CVE-2026-65353
- CVE-2026-28928
- CVE-2026-43748
- CVE-2026-65407
- CVE-2026-43776
- CVE-2026-64725
- CVE-2026-43730
- CVE-2026-64747
- CVE-2026-64707
- CVE-2026-43811
- CVE-2026-43813
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43797
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43702
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43753
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-64705
- CVE-2026-43780
- CVE-2026-43818
- CVE-2026-64716
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-43805
- CVE-2026-64749
- CVE-2026-43778
- CVE-2026-64709
- CVE-2026-64735
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-43822
- CVE-2026-64729
- CVE-2026-43814
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-28931
- CVE-2026-43817
- CVE-2026-43769
- CVE-2026-43810
- CVE-2026-64775
- CVE-2026-64720
- CVE-2026-64751
- CVE-2026-64721
- CVE-2026-65357
- CVE-2026-65371
- CVE-2026-43808
- CVE-2026-64717
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-64743
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64771
- CVE-2026-64722
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64768
- CVE-2026-64711
- CVE-2026-43812
- CVE-2026-64741
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-43762
- CVE-2026-43800
- CVE-2026-28938
- CVE-2026-64713
- CVE-2026-64730
- CVE-2026-64728
- CVE-2026-64783
- CVE-2026-64757
- CVE-2026-43804
- CVE-2026-43821
- CVE-2026-64718
- CVE-2026-64719
- CVE-2026-64726
- CVE-2026-64755
- CVE-2026-43819
- CVE-2026-43749
- CVE-2026-64767
- CVE-2026-43815
- CVE-2026-23918
- CVE-2026-64695
- CVE-2026-43781
- CVE-2026-64737
- CVE-2026-43681
- CVE-2026-43761
- CVE-2026-43672
- CVE-2026-43763
- CVE-2026-64702
- CVE-2026-64762
- CVE-2026-64698
- CVE-2026-43756
- CVE-2026-43693
- CVE-2026-43775
- CVE-2026-43759
- CVE-2026-28899
- CVE-2026-43802
- CVE-2026-64710
- CVE-2026-39875
- CVE-2026-64701
- CVE-2026-43758
- CVE-2026-64708
- CVE-2026-43783
- CVE-2026-64776
- CVE-2026-64694
- CVE-2026-43747
- CVE-2026-28945
- CVE-2026-43793
- CVE-2026-64691
- CVE-2026-43682
- CVE-2026-28981
- CVE-2026-43773
- CVE-2026-43767
- CVE-2026-43764
- CVE-2026-64697
- CVE-2026-43710
- CVE-2026-43782
- CVE-2026-64744
- CVE-2026-28982
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-64727
- CVE-2026-64723
- CVE-2026-43754
- CVE-2026-43766
- CVE-2026-64738
- CVE-2026-43806
- CVE-2026-28911
- CVE-2026-43771
- CVE-2026-43772
- CVE-2026-28912
- CVE-2026-43765
- CVE-2026-28933
- CVE-2026-64731
- CVE-2026-43694
- CVE-2026-39874
- CVE-2026-43792
- CVE-2026-43779
- CVE-2026-43777
- CVE-2026-43760
- CVE-2026-43728
- CVE-2026-43755
- CVE-2026-64745
- CVE-2026-39873
- CVE-2026-64696
- CVE-2026-64704
- CVE-2026-43774
- CVE-2026-43770
- CVE-2026-43768
- CVE-2026-84562
- CVE-2026-64703
- CVE-2026-64699
- CVE-2026-65375
- CVE-2026-43750
- CVE-2026-28932
Frequently Asked Questions
Which systems need to be updated to address this issue?
The issue is fixed in iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6. Systems running earlier affected versions should be updated to the listed fixed release.
What level of access would an attacker need to exploit this issue?
An attacker would need to run an app on the affected device, because the reported impact is that an app may be able to access sensitive user data.
What is the mitigation if an update cannot be installed immediately?
No workaround or temporary mitigation is provided in the available information. Prioritize installing the applicable fixed operating system update.