CVE-2026-64719

8.1

Apple · Safari, iOS, iPadOS, macOS, tvOS, visionOS, watchOS

An out-of-bounds access vulnerability in Apple software allows for application crashes when processing maliciously crafted web content.

Executive summary

An out-of-bounds access vulnerability affecting multiple Apple platforms could lead to service disruption via application crashes when processing malicious web content.

Vulnerability

This vulnerability involves an out-of-bounds access flaw caused by improper bounds checking during the processing of web content. It requires no authentication to trigger, though it does necessitate user interaction by convincing a victim to process maliciously crafted web content.

Business impact

The vulnerability carries a CVSS score of 8.1, reflecting a high severity due to its potential to cause significant service disruption. While the primary impact noted is an application crash, such flaws often serve as a foundation for more severe attacks, including arbitrary code execution or unauthorized information disclosure, if chained with other vulnerabilities. This poses a direct risk to business continuity and system stability across the enterprise.

Remediation

Immediate Action: Update all affected Apple devices and software to the versions specified in the vendor security advisory, specifically version 26.6 or higher where applicable.

Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected service restarts, which may indicate attempted exploitation of this memory-related flaw.

Compensating Controls: Utilize content filtering and robust network security policies to restrict access to untrusted or malicious web domains that may serve the crafted content required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of the affected software, organizations should prioritize the deployment of the provided security updates. Administrators must ensure that all managed Apple devices are patched to the recommended versions to mitigate the risk of service disruption and potential exploitation.

More Apple CVEs

Sources