Junglewise Threat Intelligence

CVE-2026-64754: Apple multiple operating systems out-of-bounds write

CVE-2026-64754 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a device to be crashed or disabled. An attacker could trigger this issue by tricking a user into opening a specially crafted file. This would result in a denial-of-service, temporarily interrupting the use of the device or its applications.

Technical details

An out-of-bounds write vulnerability exists across several Apple operating systems due to insufficient bounds checking when processing files. An attacker can exploit this by providing a maliciously crafted file to the system, which triggers an out-of-bounds memory write. The primary impact of successful exploitation is a denial-of-service (DoS) condition. Apple has addressed this issue by improving bounds checking in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6
  • Apple watchOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats