Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow flaw exists in the file processing routines of Apple operating systems. The issue was mitigated by adding stricter input validation, and it is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. When a maliciously crafted file is processed, the overflow can cause an application to terminate unexpectedly or, in some cases, allow an attacker to execute arbitrary code. This flaw is classified as CWE-190: Integer Overflow or Wraparound.

Affected Systems

Apple devices running iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected. The flaw is mitigated in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score of under 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the updated description, it is inferred that the attack vector involves the delivery of a malicious file that an application processes, potentially requiring the file to be executed by a privileged or system component. This risk is particularly high for users who accept or download untrusted content.

Generated by OpenCVE AI on August 17, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple operating systems to the patched versions (iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6).
  • For managed environments, deploy the update using your MDM solution and configure it to block execution of files from untrusted sources.
  • Enable and enforce the built-in OS sandboxing and other security controls to reduce the attack surface for any remaining or newly discovered flaws.

Generated by OpenCVE AI on August 17, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Apple File Processing Enabling Remote Code Execution

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Apple File Processing Enabling Remote Code Execution

Sun, 02 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow Allows Arbitrary Code Execution through Malicious Files on Apple Operating Systems

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Allows Arbitrary Code Execution through Malicious Files on Apple Operating Systems
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:59.063Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64766

cve-icon Vulnrichment

Updated: 2026-07-28T13:47:20.664Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:14.727

Modified: 2026-08-17T22:17:21.667

Link: CVE-2026-64766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T23:45:03Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound