CVE-2026-64754
published 2026-07-27CVE-2026-64754: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.17%
6.3th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | ipados | < 26.6 | 26.6 |
| apple | iphone_os | < 26.6 | 26.6 |
| apple | macos | < 14.8.8 | 14.8.8 |
| apple | macos | < 15.7.8 | 15.7.8 |
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 14.0 < 14.8.8 | 14.8.8 |
| apple | macos | >= 15.0 < 15.7.8 | 15.7.8 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
| apple | tvos | < 26.6 | 26.6 |
| apple | visionos | < 26.6 | 26.6 |
| apple | watchos | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.6/15.7.8/14.8.8 out-of-bounds write
vuldb·2026-07-28
CVE-2026-64754 [CRITICAL] Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.6/15.7.8/14.8.8 out-of-bounds write
A vulnerability labeled as critical has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. This issue affects some unknown processing. Such manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2026-64754. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
An out-of-bounds write issue was addressed with improved bounds checking.
ghsa_unreviewed·2026-07-27
CVE-2026-64754 [MEDIUM] CWE-787 An out-of-bounds write issue was addressed with improved bounds checking.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.
No detection rules found.
No public exploits indexed.
2026-07-27
Published