Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow flaw exists in the file processing routines of Apple operating systems. When a maliciously crafted file is processed, the overflow can cause an application to terminate unexpectedly or, more severely, enable an attacker to execute arbitrary code. The vulnerability is classified as CWE‑190: Integer Overflow or Wraparound.

Affected Systems

Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw is mitigated in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score of under 1 % shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector involves local or remote delivery of a malicious file that an application processes, potentially requiring the file to be executed by a privileged application or system component. This gives the risk particularly high for users who accept or download untrusted content.

Generated by OpenCVE AI on August 4, 2026 at 13:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple operating systems to the patched versions (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6).
  • For managed environments, deploy the update using your MDM solution and configure it to block execution of files from untrusted sources.
  • Enable and enforce the built‑in OS sandboxing and other security controls to reduce the attack surface for any remaining or newly discovered flaws.

Generated by OpenCVE AI on August 4, 2026 at 13:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Apple File Processing Enabling Remote Code Execution

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow Allows Arbitrary Code Execution through Malicious Files on Apple Operating Systems

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Allows Arbitrary Code Execution through Malicious Files on Apple Operating Systems
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-29T03:55:33.822Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64766

cve-icon Vulnrichment

Updated: 2026-07-28T13:47:20.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:14.727

Modified: 2026-07-29T05:17:05.237

Link: CVE-2026-64766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound