Junglewise Threat Intelligence

CVE-2026-64764: Apple multiple operating systems out-of-bounds write via crafted file

CVE-2026-64764 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability in Apple's operating systems, including iOS, macOS, and watchOS, could allow a malicious file to crash applications or run unauthorized code. This affects a wide range of Apple devices used for mobile communication, desktop productivity, and wearable technology. An attacker could potentially gain control over a device or access sensitive user data if a user processes a specially crafted file.

Technical details

An out-of-bounds write vulnerability exists across multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS) due to insufficient bounds checking when processing files. An attacker can exploit this by tricking a user into opening or processing a maliciously crafted file, potentially leading to arbitrary code execution or a denial-of-service (app termination). The issue was addressed by improving bounds checking in the affected components. Patches are available in iOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and other corresponding OS updates.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory: Advisory published by Apple and NVD record created.
  • 2026-07-27: patched: Fixes released in various Apple OS updates.

References

Related threats