Junglewise Threat Intelligence

CVE-2026-64770: Apple multiple operating systems out-of-bounds write

CVE-2026-64770 · Severity: info · Published 2026-07-27

Technologies: Apple Tvos, Apple macOS, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A security vulnerability exists in several Apple operating systems, including iOS, macOS, and tvOS. A remote attacker could exploit this flaw to cause applications to crash unexpectedly or corrupt system memory. This could lead to service disruptions or potentially allow further unauthorized actions on the device.

Technical details

An out-of-bounds write vulnerability exists across multiple Apple platforms due to insufficient bounds checking. A remote attacker can exploit this flaw to trigger heap corruption or cause an application to terminate unexpectedly. The vulnerability is addressed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6 by implementing improved validation of memory boundaries. No user interaction or local authentication requirements were specified in the advisory, suggesting a network-based attack vector.

Affected products

  • Apple iOS and iPadOS < 26.6
  • Apple macOS Sequoia < 15.7.8
  • Apple macOS Sonoma < 14.8.8
  • Apple macOS Tahoe < 26.6
  • Apple tvOS < 26.6
  • Apple visionOS < 26.6

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: patched

References

Related threats