ZeroHour

CVE-2026-64736

mass

Out-of-Bounds Kernel Memory Access in Apple iOS, macOS, watchOS, and tvOS

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-64736 is an out-of-bounds read/write flaw (CWE-125/CWE-787) in Apple's kernel, fixed by improved bounds checking. It is triggered locally by an app already running on the device, which may be able to read kernel memory or corrupt it, causing unexpected system termination or a device crash. The CVSS 3.1 score is 7.1 (high) with a local attack vector, low privileges required, and no user interaction, meaning any malicious or compromised app on an unpatched device is a potential vector. All users on versions prior to the fixes across iOS, iPadOS, macOS Sequoia and Tahoe, tvOS, visionOS, and watchOS are affected. No public proof of concept is known, the flaw is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Patch all Apple devices to iOS/iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, or watchOS 27 as soon as possible, prioritizing managed enterprise fleets via MDM. Because exploitation requires a local app, review and restrict sideloaded, untrusted, or out-of-date third-party apps, and audit recently installed enterprise apps for anomalous crash or kernel-panic behavior.

Affected
Apple iOSversions prior to iOS 26.6.1
Apple iPadOSversions prior to iPadOS 26.6.1
Apple macOS Sequoiaversions prior to macOS Sequoia 15.8
Apple macOS Tahoeversions prior to macOS Tahoe 26.6.2
Apple tvOSversions prior to tvOS 27
Apple visionOSversions prior to visionOS 27
Apple watchOSversions prior to watchOS 27
Estimated exposure
mass≈1 billion+ devices (Apple's active install base exceeds 2 billion devices; a large share run pre-fix OS versions) — Apple reports an active installed base of over 2 billion iPhones, iPads, Macs, and wearables, and only devices not yet updated to the July-fix versions are vulnerable, which typically represents a majority of the fleet in the weeks after…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

Vendors
apple
Products
ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-125, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.