Junglewise Threat Intelligence

CVE-2026-64766: Apple multiple operating systems integer overflow via crafted file

CVE-2026-64766 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS Tahoe, Apple watchOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A vulnerability exists in Apple's operating systems, including iOS, macOS, and watchOS, that occurs when the system processes a specially crafted file. If exploited, this could allow an attacker to crash applications or potentially gain unauthorized control over the device to execute malicious code. Users should update their devices to the latest software versions to protect against this risk.

Technical details

An integer overflow vulnerability exists across multiple Apple operating systems (iOS, iPadOS, macOS, tvOS, visionOS, and watchOS). The issue is triggered when the system processes a maliciously crafted file, suggesting a flaw in a file-parsing component or media framework. The root cause was addressed through improved input validation. Successful exploitation could lead to unexpected application termination (Denial of Service) or arbitrary code execution with the privileges of the process handling the file. The attack vector is local/file-based, typically requiring a user to open a malicious file. Fixes are available in iOS/iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, and corresponding versions for other platforms.

Affected products

  • Apple iOS and iPadOS Before 26.6
  • Apple macOS Tahoe Before 26.6
  • Apple macOS Sequoia Before 15.7.8
  • Apple macOS Sonoma Before 14.8.8
  • Apple tvOS Before 26.6
  • Apple visionOS Before 26.6
  • Apple watchOS Before 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats