VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

Apple iOS: 25 Critical Vulnerabilities Patched in Single July 2026 Disclosure

Apple released a critical security update on July 27, 2026, patching 25 vulnerabilities across its operating systems, including flaws enabling kernel code execution and sandbox escapes.

Key findings

  • Apple patched 25 vulnerabilities in iOS, iPadOS, macOS, tvOS, visionOS, and watchOS on July 27, 2026.
  • Critical flaws include memory corruption, sandbox escapes, and potential for kernel code execution.
  • Vulnerabilities addressed by improved memory management, input validation, and bounds checking.
  • All affected systems updated to iOS 26.6 and corresponding OS versions.
  • No active exploitation reported by Apple at the time of disclosure.

On July 27, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities across its iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems. The vulnerabilities, disclosed on the same day, span a range of issues including memory corruption, sandbox escapes, and unauthorized data access. Several critical flaws could lead to unexpected system termination, kernel memory corruption, or arbitrary code execution.

Several vulnerabilities were related to memory management and input validation, leading to issues such as use-after-free, integer overflows, and out-of-bounds writes. These types of vulnerabilities, including CVE-2026-64783, CVE-2026-64775, CVE-2026-64774, CVE-2026-64772, CVE-2026-64771, CVE-2026-64770, CVE-2026-64769, CVE-2026-64768, CVE-2026-64766, CVE-2026-64765, CVE-2026-64764, CVE-2026-64763, CVE-2026-64754, and CVE-2026-64739, could allow malicious applications to cause unexpected system termination or heap corruption.

A subset of these vulnerabilities, specifically CVE-2026-64766, CVE-2026-64765, CVE-2026-64764, and CVE-2026-64763, involved processing maliciously crafted files and could lead to arbitrary code execution. Additionally, CVE-2026-64747, a buffer overflow vulnerability, could enable a malicious app to execute arbitrary code with kernel privileges.

Other vulnerabilities addressed in this batch include authorization issues, such as CVE-2026-64755, CVE-2026-64746, and CVE-2026-64743, which could allow an app to access sensitive user data or add contacts without authorization. CVE-2026-64742 addressed an issue where an app might access sensitive user data by not using HTTPS for network communication. CVE-2026-64740, a parsing issue in directory path handling, could allow a malicious app to break out of its sandbox.

Apple has addressed these vulnerabilities with improved memory management, input validation, bounds checking, state management, and by enforcing additional restrictions. The fixes are available in iOS 26.6 and iPadOS 26.6, along with corresponding updates for macOS, tvOS, visionOS, and watchOS. Notably, Apple did not report any active exploitation of these CVEs at the time of disclosure.

This extensive batch of patches underscores the importance of keeping Apple devices updated to mitigate risks ranging from application crashes and data access to kernel-level code execution and sandbox escapes. Users are advised to install the latest updates promptly to protect their devices.

AI-written article. Grounded in 25 CVE records listed below.