CVE-2026-39868PoC(apple / ipados)

HIGHCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-06-30); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-09: 1Mentions · 2026-07-27: 1Mentions · 2026-08-06: 2Mentions · 2026-08-07: 2PoC Mentioned / Linked · 2026-07-09: 1PoC Mentioned / Linked · 2026-07-27: 1PoC Mentioned / Linked · 2026-08-06: 2PoC Mentioned / Linked · 2026-08-07: 2Exploit Tool / Code · 2026-08-06: 1Exploit Tool / Code · 2026-08-07: 1Active Exploitation · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-27: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-27: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 206-3007-0907-2708-0608-07
Signal classification4 categories
PoC
562.5%
Active Exploitation
112.5%
Disclosure
112.5%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-302
Active Exploitation1Disclosure1
2026-07-091
Patch1
2026-07-271
PoC1
2026-08-062
PoC2
2026-08-072
PoC2
Full discourse8 posts
  • cha2ned@destr4ctt
    PoC

    While waiting for Apple’s next security release announce, I’m publishing the details and PoC for CVE-2026-39868, a kernel memory corruption issue fixed in macOS 26.5.2: https://github.com/vschko/CaseStudies/tree/main/CVE-2026-39868

    Post summary

    The author publishes a PoC and technical details for CVE-2026-39868, a kernel memory corruption flaw mitigated by macOS 26.5.2, with no indication of active exploitation.

    21701455110.2K
    397 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Full details and PoC exploit code for CVE-2026-39868 are public. The macOS kernel vulnerability in DTrace lets an app corrupt kernel memory. Patch now. #CVE202639868 #macOS #iOS #DTrace #KernelExploit #Apple #PoC #InfoSec #CyberSecurity http://securityonline.info/cve-2026-39868-macos-dtrace/

    Post summary

    The tweet announces that the full details and PoC exploit code for CVE-2026-39868, a DTrace kernel memory corruption flaw in macOS, are publicly available and urges users to patch immediately.

    0601451.2K
    13.0K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 PoC released: Full exploit details for CVE-2026-39868, a macOS DTrace kernel vulnerability, are now public. The flaw allows a local application to corrupt kernel memory, potentially leading to system instability or further privilege escalation. PoC: https://github.com/vschko/CaseStudies/tree/main/CVE-2026-39868 #Apple #macOS #CVE #PoC #CyberSecurity #Kernel #Infosec

    Post summary

    A PoC for CVE-2026-39868, a macOS DTrace kernel memory corruption vulnerability, has been published with full exploit details and code available in a GitHub repository.

    020931.9K
    1.5K followersView on X
  • moton@moton
    PoC

    macOS Kernel Vulnerability PoC Public: CVE-2026-39868 - https://securityonline.info/cve-2026-39868-macos-dtrace/

    Post summary

    The post announces that a proof‑of‑concept for macOS kernel CVE-2026-39868 is publicly available via a provided link, but gives no further technical or exploitation details.

    01060475
    756 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are chaining WebKit and kernel exploits in Apple devices to escalate from browser-based code execution to full system control. TRC analysis shows the attack path: malicious website → arbitrary code execution (CVE-2026-43724) → privilege escalation → lateral movement across networks. Runtime segmentation helps limit blast radius when endpoints become pivot points. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/june-2026-apple-updates-cve-2026-39868

    Post summary

    Attackers are actively exploiting CVE‑2026‑43724 on Apple devices by chaining WebKit and kernel exploits to move from browser-based code execution to full system control, as detailed in the linked TRC analysis.

    01020159
    2.0K followersView on X
  • Positive Technologies Global@PTsecurity_EN
    Patch

    At first glance DTrace looked out of reach for unprivileged code. Turned out a gadget gets you there anyway 💀 PT-2026-53696 / CVE-2026-39868 (CVSS 7.0) abuses flaws in DTrace and corrupts kernel memory on macOS, iOS & iPadOS and was fixed by Apple: https://dbugs.ptsecurity.com/vulnerability/PT-2026-53696 https://t.co/mG8pwXQcmT

    Post summary

    The tweet announces a DTrace kernel memory corruption vulnerability (CVE‑2026‑39868) that was fixed by Apple, linking to detailed vendor advisories.

    00011439
    3.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Apple OS kernel input validation flaw enabling memory corruption (CVE-2026-39868) Improper input validation in Apple operating systems allows a malicious app to pass crafted data into a privileged system/kernel-facing interface, leading to unexpected system termination or kernel memory corruption. The root cause is improper input validation, resulting in a kernel memory corruption condition. An attacker exploits this by running a specially crafted app locally on a vulnerable device and triggering the vulnerable code path to feed malformed inputs into the kernel. Impact ranges from reliable denial of service (forced reboots/panics) to potential privilege escalation or code execution in kernel context if the corruption is weaponized. 👉 Affected: iOS/iPadOS/macOS prior to 26.5.2 | Upgrade to iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2

    Post summary

    The post announces the discovery of a critical kernel input‑validation flaw (CVE‑2026‑39868) that can lead to memory corruption and outlines remedial upgrades, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    00001198
    232 followersView on X
  • キタきつね@foxbook
    PoC

    CVE-2026-39868: 公開された概念実証により、macOSおよびiOSカーネルのメモリ破損の脆弱性が明らかに CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw #DailyCyberSecurity (Aug 6) https://securityonline.info/cve-2026-39868-macos-dtrace/

    Post summary

    A public PoC has disclosed a memory corruption flaw affecting macOS and iOS kernels; no exploit code, patch, or active exploitation evidence is provided.

    00000285
    4.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more