Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write vulnerability affects multiple Apple operating systems and was addressed by implementing improved bounds checking. The flaw allows a remote attacker to trigger unexpected application termination or heap corruption by writing beyond the allocated memory boundaries. The description highlights that the issue is fixed in several releases: iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.

Affected Systems

All Apple iOS, iPadOS, macOS, tvOS, and visionOS releases older than iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 are implicated, as inferred from the fix releases listed.

Risk and Exploitability

The CVSS score is 9.8, indicating a critical severity, but the EPSS score is <1%, which points to a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a remote delivery of malicious data that triggers the vulnerable code path, resulting in application termination or heap corruption. No evidence supports more advanced exploitation, such as code execution.

Generated by OpenCVE AI on August 18, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest operating‑system updates that contain the fixed releases - iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6, which close the out‑of‑bounds write flaw (CWE‑787).
  • Enable automatic system updates to receive future security patches without delay.
  • If a firmware update is unavailable, monitor for abnormal application crashes or heap corruption events, and limit the use of applications that may trigger the vulnerable code path while a fix is pending, noting that this vulnerability is a CWE‑787 out‑of‑bounds write issue.

Generated by OpenCVE AI on August 18, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple OS Leading to Application Crash

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

Mon, 03 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Apple OS Leading to Application Crash

Sun, 02 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Application Crashes and Heap Corruption in Apple OSes

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Application Crashes and Heap Corruption in Apple OSes

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:29:54.561Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64769

cve-icon Vulnrichment

Updated: 2026-07-28T15:14:48.285Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:15.020

Modified: 2026-08-17T22:17:21.990

Link: CVE-2026-64769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:30:05Z

Weaknesses