CVE-2026-64736
Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS
An out-of-bounds access vulnerability in multiple Apple operating systems allows a local application to cause system termination or kernel memory corruption.
Executive summary
An out-of-bounds access flaw in Apple software allows local low-privileged applications to corrupt kernel memory or crash the system, posing a significant risk to device stability and security.
Vulnerability
This is an out-of-bounds access vulnerability resulting from insufficient bounds checking. A local attacker with low privileges can leverage this flaw to trigger system termination or perform unauthorized kernel memory corruption.
Business impact
The vulnerability carries a CVSS score of 7.1, reflecting a high severity due to the potential for kernel-level impact. Successful exploitation could lead to denial of service via system crashes or provide a foundation for further privilege escalation by manipulating sensitive kernel memory, jeopardizing the integrity of the entire device.
Remediation
Immediate Action: Update all affected Apple devices to the specified fixed versions: iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, or tvOS/visionOS/watchOS 27.
Proactive Monitoring: Monitor system logs for repeated crash reports or unexpected kernel panics originating from non-system applications.
Compensating Controls: Ensure that third-party application installations are restricted to trusted sources to minimize the risk of malicious code execution on the local device.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for kernel-level memory corruption, administrators should prioritize patching across all managed Apple assets. Organizations should enforce a rapid deployment of the provided updates to prevent local attackers from abusing this out-of-bounds access vulnerability to compromise system integrity.
More Apple CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.1 (3.1)
- Analyst report written