CVE-2026-64771: Buffer Overflow
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
Accounts Framework. This issue was addressed with improved data protection.
— Apple
Accounts. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Accounts. An access issue was addressed with additional sandbox restrictions.
— Apple
afpfs. A buffer overflow was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 18.7.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Sequoia 15.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Tahoe 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in tvOS 26.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in visionOS 26.6 - Compensating control
This issue was addressed by using HTTPS when sending information over the network.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-64733
- CVE-2026-43801
- CVE-2026-64725
- CVE-2026-43730
- CVE-2026-64747
- CVE-2026-64707
- CVE-2026-43813
- CVE-2026-64746
- CVE-2026-64734
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43711
- CVE-2026-43714
- CVE-2026-64742
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-43780
- CVE-2026-64716
- CVE-2026-64758
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-64749
- CVE-2026-43778
- CVE-2026-64709
- CVE-2026-64735
- CVE-2026-43739
- CVE-2026-43816
- CVE-2026-43822
- CVE-2026-64729
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-43817
- CVE-2026-43724
- CVE-2026-43769
- CVE-2026-43810
- CVE-2026-64775
- CVE-2026-39868
- CVE-2026-64751
- CVE-2026-64721
- CVE-2026-4424
- CVE-2026-64739
- CVE-2026-43706
- CVE-2026-43703
- CVE-2026-64743
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64771
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64768
- CVE-2026-43812
- CVE-2026-64741
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-43704
- CVE-2026-43740
- CVE-2026-43735
- CVE-2026-64713
- CVE-2026-43734
- CVE-2026-43726
- CVE-2026-43709
- CVE-2026-43742
- CVE-2026-43699
- CVE-2026-64730
- CVE-2026-43727
- CVE-2026-64783
- CVE-2026-43725
- CVE-2026-43663
- CVE-2026-39872
- CVE-2026-43712
- CVE-2026-64728
- CVE-2026-43731
- CVE-2026-43715
- CVE-2026-64757
- CVE-2026-43713
- CVE-2026-43708
- CVE-2026-43707
- CVE-2026-43705
- CVE-2026-43701
- CVE-2026-43745
- CVE-2026-43700
- CVE-2026-43804
- CVE-2026-43732
- CVE-2026-43676
- CVE-2026-43821
- CVE-2026-43720
- CVE-2026-64718
- CVE-2026-43721
- CVE-2026-43718
- CVE-2026-64719
- CVE-2026-28979
- CVE-2026-64726
- CVE-2026-28928
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-64740
- CVE-2026-43743
- CVE-2026-43814
- CVE-2026-28931
- CVE-2026-64727
- CVE-2026-64720
- CVE-2026-43800
- CVE-2026-43770
- CVE-2026-43717
- CVE-2026-43819
- CVE-2026-43749
- CVE-2026-64767
- CVE-2026-23918
- CVE-2026-64695
- CVE-2026-43781
- CVE-2026-64737
- CVE-2026-43748
- CVE-2026-43776
- CVE-2026-43681
- CVE-2026-43672
- CVE-2026-43763
- CVE-2026-64702
- CVE-2026-64762
- CVE-2026-64698
- CVE-2026-43797
- CVE-2026-43756
- CVE-2026-43693
- CVE-2026-43775
- CVE-2026-43759
- CVE-2026-43802
- CVE-2026-64710
- CVE-2026-39875
- CVE-2026-43698
- CVE-2026-43758
- CVE-2026-64708
- CVE-2026-64776
- CVE-2026-64694
- CVE-2026-43747
- CVE-2026-28945
- CVE-2026-43793
- CVE-2026-43753
- CVE-2026-64691
- CVE-2026-43682
- CVE-2026-28981
- CVE-2026-43773
- CVE-2026-43767
- CVE-2026-43764
- CVE-2026-64697
- CVE-2026-43710
- CVE-2026-43818
- CVE-2026-43805
- CVE-2026-43782
- CVE-2026-64744
- CVE-2026-28982
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-64723
- CVE-2026-43754
- CVE-2026-28973
- CVE-2026-43766
- CVE-2026-64738
- CVE-2026-43806
- CVE-2026-28911
- CVE-2026-43733
- CVE-2026-64722
- CVE-2026-43771
- CVE-2026-43772
- CVE-2026-64711
- CVE-2026-28912
- CVE-2026-43765
- CVE-2026-64731
- CVE-2026-43694
- CVE-2026-39874
- CVE-2026-43792
- CVE-2026-43779
- CVE-2026-43777
- CVE-2026-43760
- CVE-2026-43728
- CVE-2026-43755
- CVE-2026-64745
- CVE-2026-39873
- CVE-2026-64696
- CVE-2026-64704
- CVE-2026-43774
- CVE-2026-43768
- CVE-2026-64703
- CVE-2026-64699
- CVE-2026-43750
- CVE-2026-28932
- CVE-2026-28849
- CVE-2026-28936
- CVE-2026-43738
- CVE-2026-28926
- CVE-2025-43325
- CVE-2026-43661
- CVE-2026-39877
- CVE-2026-43722
- CVE-2026-20672
- CVE-2026-28983
- CVE-2026-28900
- CVE-2026-43653
- CVE-2026-28961
- CVE-2026-28896
- CVE-2026-43665
- CVE-2026-28914
- CVE-2026-64732
- CVE-2026-43811
- CVE-2026-64755
- CVE-2026-43667
- CVE-2026-28990
- CVE-2026-64760
- CVE-2026-28996
- CVE-2026-43658
- CVE-2026-65338
- CVE-2026-43795
- CVE-2026-28984
- CVE-2026-28958
- CVE-2026-28947
- CVE-2026-65334
- CVE-2026-64784
- CVE-2026-65331
- CVE-2026-65335
- CVE-2026-65332
- CVE-2026-65333
- CVE-2026-65337
- CVE-2026-65336
- CVE-2026-65340
- CVE-2026-64781
- CVE-2026-64782
- CVE-2026-65341
- CVE-2026-64715
- CVE-2026-64780
- CVE-2026-43794
- CVE-2026-64778
- CVE-2026-64779
Frequently Asked Questions
What is the severity of CVE-2026-64771?
CVE-2026-64771 is classified with high severity due to its potential impact on device security and stability.
How do I fix CVE-2026-64771?
To mitigate CVE-2026-64771, users should update their Apple devices to the latest software version provided by Apple.
What types of vulnerabilities are involved in CVE-2026-64771?
CVE-2026-64771 includes vulnerabilities such as buffer overflow, input validation issues, and race conditions.
Which Apple products are affected by CVE-2026-64771?
CVE-2026-64771 affects several Apple products including visionOS, tvOS, iOS, iPadOS, and macOS versions Tahoe and Sequoia.
When was CVE-2026-64771 published?
CVE-2026-64771 was published on July 27, 2026.