Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a flaw in the operating system’s memory handling routines. A malicious or compromised application can leverage this weakness to overwrite or corrupt kernel memory, which can result in unexpected system termination or untrusted memory manipulation. The consequence is a loss of system availability and a potential compromise of operating‑system integrity, as kernel memory corruption can alter privileged data structures.

Affected Systems

Apple iOS, iPadOS, macOS Sequoia, macOS Tahoe, and visionOS releases prior to iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, and visionOS 26.6 are affected. Devices running a version older than these patches are vulnerable until updated.

Risk and Exploitability

The issue is exploitable by any application capable of running on the device, and based on the description, it is inferred that the attack vector is local via any application. The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score is < 1%, pointing to a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The potential impact is a system crash or compromise of privileged data, resulting in loss of availability and integrity. Attacks would require the malicious app to be installed or executed on the device, which is likely for end‑users, making the risk significant until mitigated by patching.

Generated by OpenCVE AI on August 4, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the operating system to the patched versions: iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, and visionOS 26.6.
  • Reinstall or update any third‑party applications that were installed prior to the patch to remove possible exploitation code.
  • Limit installation of applications from unknown or untrusted sources, applying the least privilege model within the system.
  • Monitor and log kernel panic events; report them to Apple for further investigation.

Generated by OpenCVE AI on August 4, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Apple OS Kernel Memory Corruption Vulnerability

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption Leading to System Termination in Apple iOS, iPadOS, macOS, and visionOS
Weaknesses CWE-122

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Kernel Memory Corruption Leading to System Termination in Apple iOS, iPadOS, macOS, and visionOS
Weaknesses CWE-122

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T17:55:31.873Z

Reserved: 2026-07-20T18:10:18.985Z

Link: CVE-2026-64749

cve-icon Vulnrichment

Updated: 2026-07-28T17:46:50.493Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.727

Modified: 2026-07-29T19:51:14.167

Link: CVE-2026-64749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer