Junglewise Threat Intelligence

CVE-2026-64692: Apple Multiple Operating Systems out-of-bounds read

CVE-2026-64692 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a malicious application to crash the device or cause a denial-of-service. This issue affects a wide range of Apple products used for mobile communication, desktop computing, and wearable technology. Exploitation could disrupt operations and prevent users from accessing their devices until they are restarted. Apple has released software updates to address this flaw by improving how the system handles memory boundaries.

Technical details

An out-of-bounds read vulnerability exists in multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw is caused by insufficient bounds checking when processing certain data, which can be triggered by a local application. An attacker could exploit this to cause a denial-of-service (DoS) by crashing the affected system. Apple addressed the root cause by implementing improved bounds checking in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats