Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write vulnerability was identified in several Apple operating systems, allowing a remote attacker to cause unexpected application termination or heap corruption. The weakness results from insufficient bounds checking during memory operations, which can destabilize the process and potentially lead to further exploitation if the corrupted memory is leveraged, although the CVE description does not indicate additional impacts beyond the corruption.

Affected Systems

Vulnerable versions include Apple iOS 26.5 and older, iPadOS 26.5 and older, macOS Sequoia 15.7.7 and earlier, macOS Sonoma 14.8.7 and earlier, macOS Tahoe 26.5 and earlier, tvOS 26.5 and earlier, and visionOS 26.5 and earlier. Apple recommends upgrading to iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 for the fix.

Risk and Exploitability

The CVSS score is 9.8, indicating a critical severity, but the EPSS score is <1%, which suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver malicious payloads that trigger the vulnerable code path, most plausibly via a remote vector. The expected effect is a denial of service through application termination or heap corruption. No evidence supports additional exploitation, such as code execution.

Generated by OpenCVE AI on August 3, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest operating-system updates that contain the fixed releases – iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.
  • Enable automatic system updates to receive future security patches without delay.
  • If an update is unavailable, monitor for abnormal application crashes or heap corruption events, and restrict use of applications that may provoke the vulnerable code path while a fix is pending.

Generated by OpenCVE AI on August 3, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple OS Leading to Application Crash

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Application Crashes and Heap Corruption in Apple OSes

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Application Crashes and Heap Corruption in Apple OSes

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:14:55.234Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64769

cve-icon Vulnrichment

Updated: 2026-07-28T15:14:48.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:15.020

Modified: 2026-07-28T18:39:55.780

Link: CVE-2026-64769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T16:30:04Z

Weaknesses