AppleCVE-2026-64705
Apple iOS and iPadOS: buffer overflow
Medium5.5CVE-2026-64705 · Published Aug 25, 2026 · updated Sep 14, 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iOS and iPadOS Product | < 26.6 | 26.6 |
| macOS Product | < 14.8.7 | 14.8.7 |
| < 15.7.7 | 15.7.7 | |
| < 26.6 | 26.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-120
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 30 | ## Impact An attacker who can choose a container or exec id may be able to... | High | 0.41.0 |
| Aug 25 | Apple iOS and iPadOS: null pointer dereference | Medium5.5 | 18.7.9+1 more |
| Aug 25 | Apple iOS and iPadOS: improper privilege management | Low3.3 | 26.5 |
| Aug 25 | Apple Safari: protection mechanism failure | High8.8 | 26.5+2 more |
| Aug 21 | Apple watchOS: improper access control | Low2.4 | 26.4 |
| Aug 21 | Apple macOS: out-of-bounds read | Medium4.3 | 14.8.5+2 more |