Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from insufficient handling of memory in the kernel, allowing a remote user to trigger memory corruption that can lead to unexpected system termination. The primary impact is denial of service through a kernel crash or memory corruption, which compromises availability. The weakness is a classic buffer overflow or use‑after‑free type error (CWE‑119).

Affected Systems

Affected systems include all Apple macOS, iOS, and iPadOS releases prior to the following patches: macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, iOS 18.7.10, and iPadOS 18.7.10. Any device running versions older than these is potentially vulnerable. The issue was identified by Apple and resolved by updating the kernel memory manager, indicating the flaw resides in the operating system kernel.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, suggesting no known exploitation yet. The CVSS score of 9.8 indicates a critical severity, with a considerable impact on confidentiality, integrity, and availability due to the kernel memory corruption. The likely attack vector is remote; a malicious user would need to exploit a remote service that interacts with kernel memory, as described by Apple, to trigger the fault. The low EPSS means the probability of real-world exploitation appears currently low, but the high severity warrants immediate patching.

Generated by OpenCVE AI on August 18, 2026 at 00:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iOS to 18.7.10 or later
  • Upgrade iPadOS to 18.7.10 or later
  • Upgrade macOS to a patched version (Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6) or later
  • Restrict remote access by disabling or securing network services that could enable remote memory corruption attacks
  • Monitor system logs for kernel panics or abrupt shutdowns, and investigate any suspicious activity promptly

Generated by OpenCVE AI on August 18, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption Leading to System Crash in macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption Leading to System Crash in macOS

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kernel memory corruption leading to system termination on macOS
Weaknesses CWE-120
CWE-416

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Kernel memory corruption leading to system termination on macOS
Weaknesses CWE-119
CWE-120
CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:31.050Z

Reserved: 2026-07-20T18:09:01.158Z

Link: CVE-2026-64695

cve-icon Vulnrichment

Updated: 2026-07-28T15:58:45.688Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:09.193

Modified: 2026-08-17T22:17:16.720

Link: CVE-2026-64695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer