Description
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-08-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Write / Potential System Crash
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic buffer overflow (CWE‑120) that occurs when an application writes data beyond the bounds of an internal kernel buffer. The flaw is caused by a missing bounds check, allowing the overflow to modify adjacent kernel memory. A malicious program or exploit that triggers the overflow can crash the system or write arbitrary data to kernel memory, potentially corrupting critical structures and enabling a denial‑of‑service or privilege‑escalation attack.

Affected Systems

Apple iOS releases prior to 26.6, iPadOS prior to 26.6, macOS Sequoia prior to 15.7.7, macOS Sonoma prior to 14.8.7, and macOS Tahoe prior to 26.6 are affected. Any device running an earlier build of these operating systems could be susceptible to the overflow if the vulnerable code path is executed.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is local—requiring the execution of a trigger application. The EPSS score is low (< 1%), and the vulnerability is not listed in CISA KEV, indicating minimal publicly known exploitation data. The CVSS score of 5.5 indicates a moderate severity; however, because the attack vector appears to be local—requiring the presence of a trigger application—the risk to systems that do not run compromised or malicious local applications is reduced. The described impact could lead to denial‑of‑service or privilege escalation, but exploitability depends on the ability to run the vulnerable code with sufficient privileges.

Generated by OpenCVE AI on September 21, 2026 at 08:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to Sequoia 15.7.7 or later, or Sonoma 14.8.7 or later.
  • Upgrade iOS to 26.6 or later, and iPadOS to 26.6 or later.
  • Restrict or remove applications that may trigger the overflow, especially those running with elevated privileges.
  • Reboot the system after patching to ensure all processes are restarted.

Generated by OpenCVE AI on September 21, 2026 at 08:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Kernel Buffer Overflow Causing System Crash or Kernel Memory Write

Mon, 21 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Kernel Buffer Overflow May Cause System Crash or Memory Write
Weaknesses CWE-119

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system termination or write kernel memory. A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Kernel Buffer Overflow May Cause System Crash or Memory Write
Weaknesses CWE-119

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system termination or write kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:23.455Z

Reserved: 2026-07-20T18:09:24.049Z

Link: CVE-2026-64705

cve-icon Vulnrichment

Updated: 2026-08-26T00:21:55.288Z

cve-icon NVD

Status : Modified

Published: 2026-08-25T20:17:00.333

Modified: 2026-09-14T21:17:13.680

Link: CVE-2026-64705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T08:45:12Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')