Description
An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds write that occurred when Apple's system code processed a specially crafted file. The bug caused the system to write beyond allocated memory bounds, potentially leading to application termination or arbitrary code execution. This flaw is classified as an out-of-bounds write (CWE-787).

Affected Systems

Affected Apple operating systems include iOS and iPadOS with a fixed version of 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8 and macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. All earlier releases lack the protective fix for the identified out-of-bounds write condition and remain vulnerable.

Risk and Exploitability

The risk is high because arbitrary code execution can compromise device integrity, confidentiality, and availability. The EPSS score is <1%, indicating a low exploitation probability, and the vulnerability is not listed in the CISA KEV, implying no known active exploitation yet. Attackers would need to provide a malicious file to the OS; protection relies on keeping devices updated and avoiding untrusted file handling.

Generated by OpenCVE AI on August 3, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Apple OS updates that include the fix (iOS 26.6 or newer, iPadOS 26.6 or newer, macOS Sequoia 15.7.8 or newer, macOS Sonoma 14.8.8 or newer, macOS Tahoe 26.6 or newer, tvOS 26.6 or newer, visionOS 26.6 or newer, watchOS 26.6 or newer).
  • Avoid opening files from untrusted sources before updating; verify the file’s integrity or source authenticity.
  • Monitor system logs and use security tools to detect abnormal application termination or unexpected code execution events.

Generated by OpenCVE AI on August 3, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Apple OS Out-of-Bounds Write Vulnerability Allowing Potential Code Execution via Malicious File

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-29T03:55:26.731Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64763

cve-icon Vulnrichment

Updated: 2026-07-28T16:05:30.698Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:14.427

Modified: 2026-07-29T19:50:10.873

Link: CVE-2026-64763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:45:03Z

Weaknesses