Junglewise Threat Intelligence

CVE-2026-64772: Apple Multiple Operating Systems out-of-bounds write

CVE-2026-64772 · Severity: info · Published 2026-07-27

Executive brief

A security vulnerability has been identified in Apple operating systems, including iOS, iPadOS, macOS, tvOS, and visionOS. This flaw could allow a remote attacker to cause an application to crash or potentially corrupt system memory. Such an exploit could lead to service disruptions or provide a foothold for further unauthorized activity on the device.

Technical details

An out-of-bounds write vulnerability exists in Apple's iOS, iPadOS, macOS, tvOS, and visionOS. The root cause is insufficient input validation, which can be triggered by a remote attacker. Successful exploitation may lead to unexpected application termination (denial of service) or heap corruption, which could potentially be leveraged for arbitrary code execution. The issue has been addressed in iOS 26.6, iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, and visionOS 26.6.

Affected products

  • Apple iOS and iPadOS before 26.6
  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Tahoe before 26.6
  • Apple tvOS before 26.6
  • Apple visionOS before 26.6

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: patched

References

Related threats