Junglewise Threat Intelligence

CVE-2026-64693: Apple multiple operating systems type confusion in image processing

CVE-2026-64693 · Severity: info · CVSS 5.5 · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems could allow a maliciously crafted image to crash a device. This affects a wide range of Apple products including iPhones, iPads, Macs, and Apple Watches. An exploit would result in a denial-of-service, potentially disrupting operations or causing temporary loss of access to the device.

Technical details

A type confusion vulnerability exists in the image processing components of multiple Apple operating systems. The issue was caused by insufficient type checks during the handling of image data. An attacker can exploit this by providing a maliciously crafted image file that, when processed by the system, leads to an application or system crash (denial-of-service). The vulnerability has been addressed in the latest OS updates by implementing improved input validation and type checks. Fixes are available in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats