Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw that was corrected through improved bounds checking may allow a remote attacker to trigger unexpected application termination or heap corruption on affected Apple operating systems. The fix has been incorporated into iOS 18.7.10 and iPadOS 18.7.10, as well as iOS 26.6 and iPadOS 26.6, and into macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.

Affected Systems

The vulnerability impacts Apple’s operating systems across devices: iOS and iPadOS, macOS Sequoia, macOS Sonoma, macOS Tahoe, tvOS, and visionOS. Fixed versions are iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6. Earlier releases do not receive the mitigation described in the advisory.

Risk and Exploitability

The CVSS score of 9.8 reflects a very high severity, while the EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attack is performed remotely, and the attacker can induce application crashes or heap corruption as a result of the out‑of‑bounds write.

Generated by OpenCVE AI on August 17, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Apple devices to at least the patched releases listed for iOS, iPadOS, macOS Sequoia, macOS Sonoma, macOS Tahoe, tvOS and visionOS.
  • Ensure the update is delivered via Apple’s system update mechanism or a mobile device management solution so that the fix is applied promptly.
  • Monitor system logs for abnormal application termination events or signs of memory corruption and investigate any suspicious activity immediately.

Generated by OpenCVE AI on August 17, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write Enables Heap Corruption or Crashes on Apple Operating Systems

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causes Application Termination or Heap Corruption
Weaknesses CWE-122

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causes Application Termination or Heap Corruption
Weaknesses CWE-122
CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:56.938Z

Reserved: 2026-07-20T18:10:43.924Z

Link: CVE-2026-64770

cve-icon Vulnrichment

Updated: 2026-07-28T13:49:31.869Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:15.117

Modified: 2026-08-17T22:17:22.150

Link: CVE-2026-64770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses