CVE-2026-64754: Processing a maliciously crafted file may lead to a denial-of-service in Apple iOS and iPadOS
CVE-2026-64754 is an out-of-bounds write vulnerability in Apple iOS and iPadOS that may lead to a denial-of-service condition when processing a maliciously crafted file. The issue was addressed by Apple with improved bounds checking and fixed in iOS 26.6 and iPadOS 26.6, among other Apple operating systems. The vulnerability has a CVSS score of 5.5, indicating medium severity. No known exploits in the wild have been reported.
AI Analysis
Technical Summary
This vulnerability involves an out-of-bounds write due to insufficient bounds checking when processing certain files on Apple iOS and iPadOS. Successful exploitation can cause a denial-of-service (DoS) condition. Apple fixed the issue in iOS 26.6 and iPadOS 26.6, along with updates to other Apple OS versions. The CVSS 3.1 vector indicates the attack requires local access with low complexity, no privileges, and user interaction, impacting availability only.
Potential Impact
An attacker who can convince a user to process a maliciously crafted file on a vulnerable Apple device may cause the device to crash or become unresponsive, resulting in a denial-of-service. There is no impact on confidentiality or integrity according to the CVSS vector. No known active exploitation has been reported.
Mitigation Recommendations
Apple has released official fixes in iOS 26.6 and iPadOS 26.6 to address this vulnerability. Users and administrators should update affected devices to these versions or later to remediate the issue. No additional mitigations are specified or required beyond applying the official updates.
CVE-2026-64754: Processing a maliciously crafted file may lead to a denial-of-service in Apple iOS and iPadOS
Description
CVE-2026-64754 is an out-of-bounds write vulnerability in Apple iOS and iPadOS that may lead to a denial-of-service condition when processing a maliciously crafted file. The issue was addressed by Apple with improved bounds checking and fixed in iOS 26.6 and iPadOS 26.6, among other Apple operating systems. The vulnerability has a CVSS score of 5.5, indicating medium severity. No known exploits in the wild have been reported.
CVSS v3.1
Score 5.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an out-of-bounds write due to insufficient bounds checking when processing certain files on Apple iOS and iPadOS. Successful exploitation can cause a denial-of-service (DoS) condition. Apple fixed the issue in iOS 26.6 and iPadOS 26.6, along with updates to other Apple OS versions. The CVSS 3.1 vector indicates the attack requires local access with low complexity, no privileges, and user interaction, impacting availability only.
Potential Impact
An attacker who can convince a user to process a maliciously crafted file on a vulnerable Apple device may cause the device to crash or become unresponsive, resulting in a denial-of-service. There is no impact on confidentiality or integrity according to the CVSS vector. No known active exploitation has been reported.
Mitigation Recommendations
Apple has released official fixes in iOS 26.6 and iPadOS 26.6 to address this vulnerability. Users and administrators should update affected devices to these versions or later to remediate the issue. No additional mitigations are specified or required beyond applying the official updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gqrj-rfc8-mvqp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64754"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6940369c2644c7f866b24e
Added to database: 07/28/2026, 23:50:14 UTC
Last enriched: 07/30/2026, 11:37:44 UTC
Last updated: 09/12/2026, 22:01:35 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.