Junglewise Threat Intelligence

CVE-2026-64716: Apple Multiple Operating Systems memory corruption via crafted image

CVE-2026-64716 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A memory handling vulnerability exists across Apple's operating systems, including iOS, macOS, and watchOS. If a user processes a specially crafted image, it could lead to memory corruption, potentially causing system instability or allowing unauthorized access to data. Users should update their devices to the latest software versions to mitigate this risk.

Technical details

A memory corruption vulnerability exists in multiple Apple operating systems due to improper memory handling when processing image files. An attacker could exploit this by providing a maliciously crafted image to a target system, leading to process memory corruption. The vulnerability affects iOS, iPadOS, macOS (Sequoia, Sonoma, and Tahoe), tvOS, visionOS, and watchOS. Apple has addressed the issue by improving memory management in the latest updates (e.g., iOS 26.6, macOS Sequoia 15.7.8). No authentication is typically required for this type of attack if the image is processed by a system service or application.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats