Description
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This buffer overflow occurs when Apple’s systems process input data without sufficiently checking bounds. Based on the description, it is inferred that a remote attacker should craft malicious input to trigger the overflow, leading to application termination or heap corruption. The flaw represents a classic buffer overflow (CWE‑119) and does not enable full remote code execution.

Affected Systems

Apple iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 are impacted by this flaw.

Risk and Exploitability

The CVSS score of 9.8 indicates high severity, while an EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver crafted data that exploits the bounds‑checking failure to cause crashes or memory corruption, but the flaw does not provide direct remote code execution.

Generated by OpenCVE AI on August 4, 2026 at 23:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Apple OS updates that contain the bounds‑checking fix for iOS, iPadOS, macOS, tvOS, and visionOS.
  • Avoid launching or interacting with applications known to be affected by the buffer overflow until the OS update is applied.
  • Configure monitoring to capture crash logs or abnormal memory usage that could indicate heap corruption.

Generated by OpenCVE AI on August 4, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Causing Application Crash and Heap Corruption in Apple Operating Systems

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Potentially Enables Remote Attacker to Cause Application Crash or Heap Corruption on Apple Devices
Weaknesses CWE-120

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Potentially Enables Remote Attacker to Cause Application Crash or Heap Corruption on Apple Devices
Weaknesses CWE-119
CWE-120
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:54.841Z

Reserved: 2026-07-20T18:10:53.025Z

Link: CVE-2026-64771

cve-icon Vulnrichment

Updated: 2026-07-28T13:59:59.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:15.213

Modified: 2026-07-28T18:39:12.377

Link: CVE-2026-64771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T00:00:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer