Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper memory handling in several Apple operating systems, which an attacker on a local network can exploit to cause a denial‑of‑service. By triggering inappropriate memory accesses, a local adversary can crash the affected system, disrupting its availability. The weakness is consistent with a resource exhaustion scenario (CWE‑400).

Affected Systems

Affected Apple products include iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Versions before iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6 are susceptible. The security update in these releases addresses the defect.

Risk and Exploitability

The EPSS score is less than 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, signifying no known mass‑targeted attacks. The CVSS score of 5.5 reflects a moderate impact when exploiting the flaw. An attacker must be on the local network and capable of sending crafted traffic to trigger the improper memory handling, which can lead to a denial‑of‑service. Given the low exploitation likelihood, the risk remains moderate but remediation is still advisable.

Generated by OpenCVE AI on August 4, 2026 at 23:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to address the memory handling flaw.
  • Restrict local network exposure by disabling unused network interfaces or applying firewall rules that limit communication from untrusted devices.
  • Monitor system logs for abnormal crashes or repeated denial‑of‑service incidents following a local network attack attempt.

Generated by OpenCVE AI on August 4, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper Memory Handling Allows Local Denial of Service on Apple Devices

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Network Denial-of-Service via Improper Memory Handling Across Apple Platforms
Weaknesses CWE-119
CWE-416

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Network Denial-of-Service via Improper Memory Handling Across Apple Platforms
Weaknesses CWE-119
CWE-400
CWE-416
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:33:16.085Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64724

cve-icon Vulnrichment

Updated: 2026-07-28T14:33:07.551Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:11.350

Modified: 2026-07-28T19:52:06.387

Link: CVE-2026-64724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption