Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read occurs when an application reads beyond the intended memory region due to insufficient bounds checking. Apple has addressed this by improving bounds checking, with fixes in iOS 18.7.10, iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Until these updates are applied, an attacker could trigger unexpected system termination, effectively denying availability to the user.

Affected Systems

Apple macOS is affected. Versions prior to Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 contain the vulnerability; those releases and later include the fix.

Risk and Exploitability

The CVSS score of 9.8 indicates severe impact, yet the EPSS score is < 1% and the flaw is not listed in CISA KEV, suggesting low current exploitation likelihood. It is inferred that the attack vector is local, requiring a malicious application to run with sufficient privileges to trigger the bounds error. The risk can be considered moderate until the update is applied.

Generated by OpenCVE AI on August 17, 2026 at 23:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest macOS update (Sequoia 15.7.8, Sonoma 14.8.8, Tahoe 26.6 or later) to correct the out-of-bounds read and related bounds-checking issue.
  • If an update cannot be applied immediately, restrict the execution of untrusted or potentially malicious applications that could intentionally trigger the bounds error.
  • Deploy log monitoring and set alerts for abnormal application exits to detect exploitation attempts and mitigate potential denial-of-service incidents.

Generated by OpenCVE AI on August 17, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Leading to System Crash in macOS

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Leading to System Crash in macOS

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Unexpected System Termination in macOS
Weaknesses CWE-119
CWE-200

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read Causing Unexpected System Termination in macOS
Weaknesses CWE-119
CWE-125
CWE-200
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:44.602Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64762

cve-icon Vulnrichment

Updated: 2026-07-28T14:51:58.373Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:14.317

Modified: 2026-08-17T22:17:21.030

Link: CVE-2026-64762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:00:05Z

Weaknesses