Description
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write issue was identified in several Apple operating systems. The vulnerability allows a remote attacker to send crafted input that can corrupt heap memory or cause application termination. It is fixed in iOS 18.7.10, iPadOS 18.7.10, iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6, meaning earlier versions remain vulnerable. The main impact is service disruption due to application crashes or memory corruption.

Affected Systems

Apple’s mobile and desktop operating systems are affected. Devices running iOS versions earlier than 18.7.10, iOS versions earlier than 26.6, iPadOS versions earlier than 18.7.10, iPadOS versions earlier than 26.6, macOS Sequoia versions earlier than 15.7.8, macOS Tahoe versions earlier than 26.6, tvOS versions earlier than 26.6, and visionOS versions earlier than 26.6 are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability, and the EPSS score of less than 1 % suggests a low but nonzero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploitation. A remote attacker can trigger the flaw by delivering malicious input from outside the device, likely causing application termination or memory corruption.

Generated by OpenCVE AI on August 18, 2026 at 00:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS update versions for iOS 18.7.10, iOS 26.6, iPadOS 18.7.10, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 to apply the fix
  • Enable Automatic Software Updates or manually apply the latest OS patches to ensure the issue is permanently patched
  • Monitor system logs, crash reports, and heap usage for abnormal application termination or memory corruption, and investigate any anomalies promptly

Generated by OpenCVE AI on August 18, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Apple OS Out‑of‑Bounds Write Leading to Heap Corruption or Application Crash

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Apple OS Out‑of‑Bounds Write Leading to Heap Corruption or Application Crash

Wed, 05 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Heap Corruption and Application Termination
Weaknesses CWE-119

Thu, 30 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write Causing Heap Corruption and Application Termination
Weaknesses CWE-119

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-17T21:30:23.734Z

Reserved: 2026-07-20T18:10:53.025Z

Link: CVE-2026-64772

cve-icon Vulnrichment

Updated: 2026-07-28T17:43:51.012Z

cve-icon NVD

Status : Modified

Published: 2026-07-27T21:17:15.317

Modified: 2026-08-17T22:17:22.467

Link: CVE-2026-64772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:45:05Z

Weaknesses