Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination.
Published: 2026-07-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE identifies an out‑of‑bounds write flaw that was mitigated with enhanced bounds checking. The bug can allow an attacker to trigger an unexpected application termination, effectively amounting to a denial of service. The weakness is a classic memory corruption fault (CWE‑787) and does not provide remote code execution or data disclosure.

Affected Systems

Apple iOS and iPadOS versions older than 18.7.10/26.6, macOS versions older than Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6, and all tvOS, visionOS, and watchOS releases prior to 26.6 are affected by this flaw.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation is currently uncommon. The CVSS score of 8.8 classifies it as high severity. Based on the statement that an attacker may cause application crashes, the most likely attack vector is a local or a specially crafted payload delivered to a vulnerable app, as no remote exploitation is documented. The resulting risk is therefore high in terms of potential service disruption, but the likelihood of successful attack remains low.

Generated by OpenCVE AI on August 18, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple operating‑system update that includes the fix (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6).
  • Reboot the device after updating to fully activate the enhanced bounds checking.
  • If an OS upgrade cannot be performed immediately, remove or disable applications that could trigger the out‑of‑bounds write until the patch is applied.

Generated by OpenCVE AI on August 18, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causes Application Crashes in Apple OSes

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination.
References

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causes Application Crashes in Apple OSes

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Allowing Unexpected App Termination
Weaknesses CWE-119

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Allowing Unexpected App Termination
Weaknesses CWE-119
CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:30.961Z

Reserved: 2026-07-20T18:09:54.848Z

Link: CVE-2026-64739

cve-icon Vulnrichment

Updated: 2026-07-28T14:33:31.123Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:12.777

Modified: 2026-08-17T22:17:19.353

Link: CVE-2026-64739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses