CVE-2026-64752

Apple · iOS, iPadOS, macOS, visionOS

A memory corruption vulnerability in Apple operating systems allows local attackers to achieve arbitrary code execution by processing a malicious image file.

Executive summary

A critical memory corruption vulnerability in Apple iOS, iPadOS, macOS, and visionOS enables arbitrary code execution, posing a significant risk to device integrity and user data.

Vulnerability

This is a memory corruption issue triggered by the processing of a maliciously crafted image. The vulnerability requires local access and user interaction to execute, as indicated by the CVSS vector (AV:L/UI:R).

Business impact

The ability to achieve arbitrary code execution grants an attacker full control over the affected device, potentially leading to unauthorized data access, installation of persistent malware, or complete system compromise. While the CVSS score of 7.3 reflects the requirement for local access and user interaction, the potential for total system compromise makes this a high-priority security concern for enterprise environments using Apple hardware.

Remediation

Immediate Action: Update all affected Apple devices to version 27 or later to implement the vendor provided fix.

Proactive Monitoring: Monitor device security logs for unusual crashes or unexpected process behavior that may indicate attempts to exploit memory corruption.

Compensating Controls: Ensure that users exercise caution when opening images from untrusted sources and maintain up-to-date endpoint protection software where applicable.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of arbitrary code execution, organizations should prioritize the deployment of the version 27 update across all managed Apple devices. Promptly patching these operating systems is the most effective method to eliminate the underlying memory corruption risk and protect organizational assets from potential exploitation.

More Apple CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.3 (3.1)
  4. Analyst report written

Sources