CVE-2026-64766
published 2026-07-27CVE-2026-64766: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
8.0th percentile
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 18.7.10 | 18.7.10 |
| apple | ios_and_ipados | < 26.6 | 26.6 |
| apple | ipados | < 26.6 | 26.6 |
| apple | iphone_os | < 26.6 | 26.6 |
| apple | macos | < 14.8.8 | 14.8.8 |
| apple | macos | < 15.7.8 | 15.7.8 |
| apple | macos | < 26.6 | 26.6 |
| apple | macos | >= 14.0 < 14.8.8 | 14.8.8 |
| apple | macos | >= 15.0 < 15.7.8 | 15.7.8 |
| apple | macos | >= 26.0 < 26.6 | 26.6 |
| apple | tvos | < 26.6 | 26.6 |
| apple | visionos | < 26.6 | 26.6 |
| apple | watchos | < 26.6 | 26.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.6 integer overflow
vuldb·2026-07-28
CVE-2026-64766 Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.6 integer overflow
A vulnerability marked as very critical has been reported in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. This affects an unknown function. The manipulation leads to integer overflow.
This vulnerability is referenced as CVE-2026-64766. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
An integer overflow was addressed with improved input validation.
ghsa_unreviewed·2026-07-27
CVE-2026-64766 [HIGH] CWE-190 An integer overflow was addressed with improved input validation.
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
https://support.apple.com/en-us/128066https://support.apple.com/en-us/128067https://support.apple.com/en-us/128068https://support.apple.com/en-us/128069https://support.apple.com/en-us/128070https://support.apple.com/en-us/128071https://support.apple.com/en-us/128072https://support.apple.com/en-us/148287
2026-07-27
Published