CVE-2026-64736

Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS

An out-of-bounds access vulnerability in multiple Apple operating systems allows a local application to cause system termination or kernel memory corruption.

Executive summary

An out-of-bounds access flaw in Apple software allows local low-privileged applications to corrupt kernel memory or crash the system, posing a significant risk to device stability and security.

Vulnerability

This is an out-of-bounds access vulnerability resulting from insufficient bounds checking. A local attacker with low privileges can leverage this flaw to trigger system termination or perform unauthorized kernel memory corruption.

Business impact

The vulnerability carries a CVSS score of 7.1, reflecting a high severity due to the potential for kernel-level impact. Successful exploitation could lead to denial of service via system crashes or provide a foundation for further privilege escalation by manipulating sensitive kernel memory, jeopardizing the integrity of the entire device.

Remediation

Immediate Action: Update all affected Apple devices to the specified fixed versions: iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, or tvOS/visionOS/watchOS 27.

Proactive Monitoring: Monitor system logs for repeated crash reports or unexpected kernel panics originating from non-system applications.

Compensating Controls: Ensure that third-party application installations are restricted to trusted sources to minimize the risk of malicious code execution on the local device.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for kernel-level memory corruption, administrators should prioritize patching across all managed Apple assets. Organizations should enforce a rapid deployment of the provided updates to prevent local attackers from abusing this out-of-bounds access vulnerability to compromise system integrity.

More Apple CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.1 (3.1)
  4. Analyst report written

Sources