Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.
Published: 2026-07-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper write to an invalid memory region allows an application to corrupt memory and crash the system, resulting in a denial‑of‑service. The flaw stems from a boundary check that still permits an out‑of‑bounds write, causing the affected operating system to terminate unexpectedly. The impact is limited to service availability, as there is no evidence that the write leads to remote code execution or data disclosure.

Affected Systems

Vulnerable Apple operating systems include iOS, iPadOS, macOS Sequoia, macOS Sonoma, macOS Tahoe, tvOS, visionOS, and watchOS when the version is older than iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6. Devices running these pre‑fixed releases can experience application or system crashes if exploited.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA KEV, indicating the likelihood of a public exploit is low. The attack vector is inferred to be a malicious or compromised application that runs with sufficient privileges to trigger the out‑of‑bounds write. While no commercial exploit is known, any app that can invoke the affected subsystem could cause a denial‑of‑service, potentially disrupting device functionality.

Generated by OpenCVE AI on August 12, 2026 at 12:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest iOS, iPadOS, macOS, tvOS, visionOS, or watchOS versions that include the fix.
  • Implement application controls such as MDM restrictions or App Store‑only installation to limit the installation of potentially malicious software.
  • Monitor system logs for abnormal crashes and be prepared to roll back if instability surfaces, though a patch is the definitive controller.

Generated by OpenCVE AI on August 12, 2026 at 12:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Denial‑of‑Service in Apple OS

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Denial of Service in Apple Operating Systems
Weaknesses CWE-787

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Leading to Denial of Service in Apple Operating Systems
Weaknesses CWE-787

Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T19:08:25.360Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:11.447

Modified: 2026-07-29T19:54:56.290

Link: CVE-2026-64725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:15:04Z

Weaknesses