CVE-2026-65329Disclosure(apple / ipados)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-19: 108-1908-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-201
Patch1
Full discourse2 posts
  • えり|缶ビール片手のAI / ガジェットウォッチャー@eri_ai_lav
    Disclosure

    ②WebKit以外の残り8件で怖いのはこの2つ ・ImageIO(CVE-2026-65346) 画像処理フレームワーク。画像を処理するだけで任意のコードが実行される恐れ。届いた1枚の画像が入口になる。 ・Telephony(CVE-2026-65329) IPSec認証を回避され、ネットワーク通信を傍受される可能性。対象はiPhone 11以降。

    Post summary

    The post highlights two newly disclosed Apple CVEs: CVE‑2026‑65346 enables arbitrary code execution via ImageIO, and CVE‑2026‑65329 may allow IPSec authentication bypass and traffic sniffing on iPhone 11+ devices.

    10000201
    44 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Apple、WebKit脆弱性21件をmacOS Tahoe 26.6.2/iOS 26.6.1で修正 旧版iOSでは42件に対応(CVE-2026-65329 他) https://rocket-boys.co.jp/security-measures-lab/apple-webkit-vulnerabilities-macos-ios-cve-2026-65329/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Apple has released patches for 21 WebKit vulnerabilities on macOS Tahoe 26.6.2 and iOS 26.6.1, with additional fixes for older iOS versions, without providing any exploit details or claims of active exploitation.

    00000274
    550 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more