Junglewise Threat Intelligence

CVE-2026-64765: Apple Multiple Operating Systems integer overflow via crafted file

CVE-2026-64765 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

Apple has released security updates for various operating systems to address a vulnerability that could allow a malicious file to crash an application or execute unauthorized code. This affects iPhones, iPads, Macs, Apple Watches, and Apple TV devices. If exploited, an attacker could potentially gain control over the device or access sensitive information by tricking a user into opening a specially crafted file.

Technical details

An integer overflow vulnerability exists in multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The issue stems from insufficient input validation when processing specially crafted files. A local attacker can exploit this by providing a malicious file that, when processed by the system, triggers the overflow. Successful exploitation can lead to unexpected application termination (Denial of Service) or arbitrary code execution with the privileges of the affected process. Apple addressed the issue by improving input validation in the latest software updates.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple macOS Tahoe Before 26.6
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats