[ << ALL_FEED ]

We helped Apple fix a vulnerability in the kernel of its operating systems

More in General

We helped Apple fix a vulnerability in the kernel of its operating systems

PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system shutdown (kernel panic) or kernel memory corruption in Apple products.

⚠️ Vulnerability PT-2026-76847 (CVE-2026-65330) received a medium severity level — 6.5 on the CVSS 3.x scale.

Sharing the details

• The bug was discovered in the BSD subsystem of the XNU network stack (the macOS and iOS kernel) in the NECP (Network Extension Control Policy) component, which manages access rights of programs and applications to network interfaces.

• Interacting with NECP requires a process with privileged rights that is digitally signed (platform-signed).

• When an NECP session is closed, the kernel correctly frees the domain filters, but the domain trie (a prefix tree of domains) remains in the global list with a pointer to the already freed session memory.

• When a trie is deleted by identifier (ID), the kernel does not verify the owner.

• Any other session can delete someone else’s prefix tree, which can result in an error and cause the kernel to panic.

🍏 Update your devices as soon as possible

Apple has already released a security fix in iOS/iPadOS 26.6.1, macOS 26.6.2, tvOS 27, watchOS 27 and visionOS 27.

Detailed information about the fixes has been published on Apple’s official pages: macOS, iOS and iPadOS, tvOS, watchOS and visionOS.

#cve #ir #ios #macos
@ptescalator

More from oUth0R

More from oUth0R

More in General