Junglewise Threat Intelligence

CVE-2026-64758: Apple Multiple Operating Systems denial of service via crafted file

CVE-2026-64758 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for various operating systems to address a vulnerability that could cause applications to crash. The issue occurs when the system processes a specifically crafted file, potentially leading to a denial-of-service condition for the affected app. Users are advised to update their devices to the latest versions to ensure stability and security.

Technical details

A vulnerability exists in multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient bounds checking when processing files. An attacker could exploit this by providing a maliciously crafted file to a vulnerable system, triggering an out-of-bounds condition. The primary impact is unexpected application termination (denial of service). Apple has addressed the root cause by implementing improved bounds checks in the affected components. The fix is available in version 26.6 across all impacted platforms.

Affected products

  • Apple iOS Before 26.6
  • Apple iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats