Junglewise Threat Intelligence

CVE-2026-64747: Apple Multiple Operating Systems buffer overflow in Kernel

CVE-2026-64747 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability has been identified in Apple's operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. A malicious application installed on a device could exploit this flaw to execute unauthorized code with the highest level of system privileges (kernel privileges). This could allow an attacker to gain full control over the device, access sensitive user data, or disrupt system operations.

Technical details

This vulnerability is a buffer overflow resulting from insufficient size validation in the kernel or a related system component across Apple's OS ecosystem. A local attacker can exploit this by running a specially crafted application on the target device. Successful exploitation allows the application to bypass sandbox restrictions and execute arbitrary code with kernel-level privileges, leading to a complete system compromise. Apple has addressed the issue by implementing improved input validation in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats