CVE-2026-64764

7.8

Apple · iOS, iPadOS, macOS, tvOS, visionOS, watchOS

An out-of-bounds write vulnerability exists in multiple Apple operating systems, allowing a maliciously crafted file to trigger arbitrary code execution or unexpected application termination.

Executive summary

A critical out-of-bounds write vulnerability in Apple software products allows for potential arbitrary code execution via the processing of a malicious file.

Vulnerability

This is an out-of-bounds write vulnerability stemming from improper bounds checking. An unauthenticated attacker can trigger this flaw by enticing a user to process a maliciously crafted file, which may result in arbitrary code execution on the host system.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its high potential for impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to execute arbitrary code with user level privileges, leading to unauthorized data access, system compromise, or complete application instability.

Remediation

Immediate Action: Update all affected Apple devices to the latest versions (iOS/iPadOS 18.7.10 or 26.6, macOS 14.8.8, 15.7.8, or 26.6, and relevant 26.6 versions for tvOS, visionOS, and watchOS) as specified in the official vendor advisories.

Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected processes initiating after file-handling operations.

Compensating Controls: Implement endpoint protection software capable of identifying and blocking malicious file signatures to reduce the risk of exploitation while patching is underway.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The potential for arbitrary code execution necessitates prompt attention despite the requirement for user interaction. Organizations should prioritize the deployment of the provided security updates across all managed Apple hardware to eliminate the risk of exploitation.

More Apple CVEs

Sources