2026-07-27 20:13CVE-2026-64726apple
PUBLISHED5.2

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.

Problem type

  • An attacker in physical proximity may be able to corrupt process memory

Affected products

Apple

iOS and iPadOS

< 26.6 - AFFECTED

macOS

< 26.6 - AFFECTED

tvOS

< 26.6 - AFFECTED

visionOS

< 26.6 - AFFECTED

watchOS

< 26.6 - AFFECTED

References

GitHub Security Advisories

GHSA-2mph-r28x-7hfp

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS...

https://github.com/advisories/GHSA-2mph-r28x-7hfp

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-64726
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-64726",
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "dateUpdated": "2026-07-28T13:51:33.889Z",
    "dateReserved": "2026-07-20T18:09:47.192Z",
    "datePublished": "2026-07-27T20:13:56.070Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple",
        "dateUpdated": "2026-07-27T20:13:56.070Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory."
        }
      ],
      "affected": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "visionOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "26.6"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "An attacker in physical proximity may be able to corrupt process memory"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.apple.com/en-us/128066"
        },
        {
          "url": "https://support.apple.com/en-us/128067"
        },
        {
          "url": "https://support.apple.com/en-us/128068"
        },
        {
          "url": "https://support.apple.com/en-us/128069"
        },
        {
          "url": "https://support.apple.com/en-us/128070"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-07-28T13:51:33.889Z"
        },
        "title": "CISA ADP Vulnrichment",
        "problemTypes": [
          {
            "descriptions": [
              {
                "lang": "en",
                "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                "cweId": "CWE-119",
                "type": "CWE"
              }
            ]
          }
        ],
        "metrics": [
          {
            "cvssV3_1": {
              "version": "3.1",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "attackVector": "NETWORK",
              "attackComplexity": "LOW",
              "privilegesRequired": "NONE",
              "userInteraction": "NONE",
              "scope": "UNCHANGED",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL"
            }
          },
          {}
        ]
      }
    ]
  }
}