Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write triggered when a maliciously crafted file is processed by the operating system. The flaw results from insufficient bounds checking during file handling, allowing the attacker to corrupt memory and cause a crash. This can lead to a denial of service for the affected Apple devices, as indicated by the CVSS score of 5.5 and the CWE‑787 classification.

Affected Systems

Apple products are affected. Vulnerable releases include iOS and iPadOS versions prior to 26.6, macOS Sequoia before 15.7.8, macOS Sonoma before 14.8.8, macOS Tahoe before 26.6, tvOS before 26.6, visionOS before 26.6, and watchOS before 26.6. The fix has been released in the listed newer versions.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1 % shows a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no public exploits yet. The likely attack vector is the delivery of a malicious file through downloads, email attachments, or connected storage – these are inferred because the description states that processing a maliciously crafted file may trigger the flaw. Successful exploitation would crash the operating system or critical services, resulting in denial of service.

Generated by OpenCVE AI on August 4, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS update that contains the fix – for example, iOS 26.6 or later, iPadOS 26.6 or later, macOS Sequoia 15.7.8 or later, macOS Sonoma 14.8.8 or later, macOS Tahoe 26.6 or later, tvOS 26.6 or later, visionOS 26.6 or later, and watchOS 26.6 or later.
  • Enable and maintain automatic security updates on all Apple devices to receive the fix promptly.
  • Until the patch is deployed, limit the handling of untrusted or unknown files by using strict file‑type validation or sandboxed file processing mechanisms to minimize exposure.

Generated by OpenCVE AI on August 4, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causes Denial of Service via Malicious File Processing on Apple OSes

Sat, 01 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Causes Denial of Service via Malicious File Processing on Apple OSes

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T18:39:53.073Z

Reserved: 2026-07-20T18:10:30.632Z

Link: CVE-2026-64754

cve-icon Vulnrichment

Updated: 2026-07-28T18:34:18.754Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:13.920

Modified: 2026-07-29T19:50:43.773

Link: CVE-2026-64754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:45:03Z

Weaknesses