Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who is within close physical proximity to an Apple device can trigger a memory corruption flaw caused by improper handling of buffer boundaries in the operating system’s memory routines. This flaw aligns with CWE‑119 and can lead to corrupted process memory, potentially causing application crashes, instability, or unintended behavior. Although the description does not state that arbitrary code execution is possible, compromising memory integrity can undermine system reliability and expose the device to further attacks if an attacker can manipulate execution flow after the corruption occurs.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS devices that are running any software version prior to 26.6 are vulnerable, as the issue is fixed only in the 26.6 releases of each operating system.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability, yet the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low expected exploitation probability under normal conditions. The attack vector requires physical proximity, so an attacker must be near the device to trigger the memory corruption. No publicly documented exploit is available; however, high severity memory corruption flaws are generally considered high risk due to their potential to destabilize applications and enable further attacks.

Generated by OpenCVE AI on August 5, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the iOS 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).
  • Install the iPadOS 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).
  • Install the macOS Tahoe 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).
  • Install the tvOS 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).
  • Install the visionOS 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).
  • Install the watchOS 26.6 or later update to address the buffer‑overflow memory corruption flaw (CWE‑119).

Generated by OpenCVE AI on August 5, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory. The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
References

Wed, 05 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Physical Proximity Memory Corruption on Apple Operating Systems

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Physical-Contact Memory Corruption Vulnerability on Apple Operating Systems
Weaknesses CWE-125

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Physical-Contact Memory Corruption Vulnerability on Apple Operating Systems
Weaknesses CWE-125

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:55.824Z

Reserved: 2026-07-20T18:09:47.192Z

Link: CVE-2026-64726

cve-icon Vulnrichment

Updated: 2026-07-28T13:51:25.316Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:11.543

Modified: 2026-08-17T22:17:18.557

Link: CVE-2026-64726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:45:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer