CVE-2026-65343 is a use-after-free vulnerability in the Apple kernel. Improper lifetime management of kernel memory may allow a remote attacker to trigger unexpected system termination. Apple addressed the issue through improved memory management.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, a README, and one Objective-C/C proof-of-concept at poc/poc_aks_oob.m. The PoC targets the claimed CVE-2026-65343 AppleKeyStore _LibSer_SEPControl_Deserialize out-of-bounds read affecting iOS/iPadOS 26.6 and earlier, reported fixed in 26.6.1. It dynamically resolves selected IOKit APIs, installs a DYLD_INTERPOSE replacement for IOConnectCallMethod, and triggers Secure Enclave key generation/signing through Security.framework. When the framework makes an in-process ACM request, the hook captures its io_connect_t and a nonzero 16-byte request handle. The PoC then reuses that handle while probing 163 AppleKeyStore selectors with a declared length of 0x800, scans returned buffers for kernel-address patterns, and attempts KASLR-slide calculation. A fallback path opens AppleKeyStore and probes using a zero handle, primarily to test path reachability when handle capture fails. No remote hosts, IP addresses, DNS names, or command-and-control infrastructure are present; the only URL in the README is a reference to an Apple security advisory and is not used by the exploit code. The supplied source is partially truncated in the analysis input, but the visible code and README describe a functional local information-disclosure PoC rather than a detection-only script or destructive fake.
This three-file repository contains an MIT license, a README, and one Objective-C/C proof-of-concept source file, poc/poc_aks_oob.m. It targets the claimed AppleKeyStore _LibSer_SEPControl_Deserialize out-of-bounds read (CVE-2026-65343) on iOS/iPadOS 26.6 and earlier. The source dynamically resolves IOKit APIs, installs a DYLD_INTERPOSE replacement for IOConnectCallMethod, and triggers Secure Enclave key creation/signing through Security.framework. If that signing operation makes an in-process IOKit request, the hook captures an IOKit connection and a nonzero 16-byte ACM handle. The PoC then replays crafted requests with a declared length of 0x800 against 163 AppleKeyStore selectors, scans returned buffers for likely kernel pointers, and attempts KASLR-slide calculation. A zero-handle fallback is included to test reachability when the signing path instead routes through secd XPC. The repository is a standalone local kernel-information-disclosure PoC rather than a framework module; its direct impact is kernel address disclosure/KASLR defeat, not arbitrary code execution.
This is a small standalone Objective-C/C proof-of-concept repository: LICENSE, a README describing the claimed AppleKeyStore out-of-bounds-read vulnerability, and poc/poc_aks_oob.m containing the exploit chain. It is not a Metasploit, Nuclei, or other exploit-framework module. The PoC dynamically resolves several IOKit symbols, defines a DYLD_INTERPOSE hook for IOConnectCallMethod, and arms that hook while generating and using a Secure Enclave P-256 key through Security.framework. When an in-process call contains a nonzero 16-byte input header, the hook records the IOKit connection and presumed ACM handle. It then reuses those values while probing 163 AppleKeyStore selectors with a hard-coded declared length of 0x800. The intended vulnerability is an alleged missing bounds check in _LibSer_SEPControl_Deserialize, causing copyout to disclose adjacent kernel heap data. Output is scanned for kernel-pointer-shaped values and, if possible, converted to a KASLR slide using a known symbol offset. The fallback route explicitly opens the AppleKeyStore service and probes using a zero handle, but is described as unlikely to pass ACM validation. The repository provides a functional exploit design for local kernel-address disclosure/KASLR defeat rather than a detection-only script; its hard-coded probe parameters and target-specific offset make it operational rather than broadly weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed in Apple TV version 27.
Remote use-after-free issue.
Out-of-bounds read permitting system termination or kernel-memory disclosure.
Remotely triggerable use-after-free causing system termination.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.