Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write vulnerability was discovered in Apple operating systems. Improved bounds checking has addressed the issue, which was fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. Processing a maliciously crafted file can cause unexpected application termination or, more critically, arbitrary code execution. The flaw originates from insufficient bounds checks during file processing, allowing an attacker to overwrite memory beyond the intended area and hijack the execution flow.

Affected Systems

Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are impacted. The issue is resolved in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. The official Apple support references contain further details.

Risk and Exploitability

Because the vulnerability exploits an out‑of‑bounds write, a remote attacker can trigger it by supplying a malicious file to any vulnerable application. The CVSS score of 7.8 indicates high severity, and the EPSS score is < 1% while it is not listed in CISA’s KEV catalog. However, the potential for arbitrary code execution across multiple Apple platforms indicates a high risk to confidentiality, integrity, and availability of affected devices.

Generated by OpenCVE AI on August 18, 2026 at 00:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, or watchOS 26.6 to fix the out‑of‑bounds write vulnerability.
  • Block or quarantine any maliciously crafted files before they reach the operating systems or limit the applications that can process external files.
  • Apply rigorous input validation and bounds checking in any custom code that handles file parsing, addressing the underlying buffer overflow weakness.

Generated by OpenCVE AI on August 18, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple OS File Processing Allows Arbitrary Code Execution

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple OS File Processing Allows Arbitrary Code Execution

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Leading to Arbitrary Code Execution via Malicious File
Weaknesses CWE-119
CWE-788

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Leading to Arbitrary Code Execution via Malicious File
Weaknesses CWE-119
CWE-787
CWE-788
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:20.882Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64764

cve-icon Vulnrichment

Updated: 2026-07-28T14:24:14.919Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:14.523

Modified: 2026-08-17T22:17:21.350

Link: CVE-2026-64764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses