Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Apple’s operating systems can allow a malicious application to use a freed memory reference, potentially causing unexpected system termination or writing data to kernel memory. The vulnerability is rooted in insufficient memory management and is identified as a classic use‑after‑free weakness. The impact includes system instability and the possibility of writing to privileged memory, which could elevate an attacker’s privileges if combined with additional exploits.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS versions prior to 26.6 are susceptible. The flaw is fixed in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 9.8 indicates very high severity. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but its high severity and kernel‑level impact make it a high‑risk condition. A malicious application can trigger the use‑after‑free during its execution, providing an attacker with a pathway to corrupt kernel memory or cause a system crash. Without a KEV listing, defenders should treat this as a potentially active threat pending new evidence and apply the vendor patch promptly.

Generated by OpenCVE AI on August 4, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest macOS, iOS, iPadOS, tvOS, visionOS, and watchOS updates (26.6 or newer) on all affected devices.
  • After applying the update, restart devices to ensure the new memory safety mechanisms are activated.
  • If an update cannot be applied immediately, defer installation of untrusted third‑party applications and monitor Apple support for any urgent patches or additional guidance.

Generated by OpenCVE AI on August 4, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Kernel Memory Corruption or System Crash across Apple OSes

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Leading to Kernel Memory Corruption or System Crash across Apple OSes
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:12:15.384Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64751

cve-icon Vulnrichment

Updated: 2026-07-28T14:12:03.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.823

Modified: 2026-07-28T18:42:37.177

Link: CVE-2026-64751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses