We helped Apple fix a vulnerability in the kernel of its operating systems
More in General
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Drama Rat: a malicious app that, once installed, really does make you sad
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples…
We helped Apple fix a vulnerability in the kernel of its operating systems
PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system shutdown (kernel panic) or kernel memory corruption in Apple products.
⚠️ Vulnerability PT-2026-76847 (CVE-2026-65330) received a medium severity level — 6.5 on the CVSS 3.x scale.
Sharing the details
• The bug was discovered in the BSD subsystem of the XNU network stack (the macOS and iOS kernel) in the NECP (Network Extension Control Policy) component, which manages access rights of programs and applications to network interfaces.
• Interacting with NECP requires a process with privileged rights that is digitally signed (platform-signed).
• When an NECP session is closed, the kernel correctly frees the domain filters, but the domain trie (a prefix tree of domains) remains in the global list with a pointer to the already freed session memory.
• When a trie is deleted by identifier (ID), the kernel does not verify the owner.
• Any other session can delete someone else’s prefix tree, which can result in an error and cause the kernel to panic.
🍏 Update your devices as soon as possible
Apple has already released a security fix in iOS/iPadOS 26.6.1, macOS 26.6.2, tvOS 27, watchOS 27 and visionOS 27.
Detailed information about the fixes has been published on Apple’s official pages: macOS, iOS and iPadOS, tvOS, watchOS and visionOS.
#cve #ir #ios #macos
@ptescalator
More in General
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Drama Rat: a malicious app that, once installed, really does make you sad
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples…




