VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

Apple Patches 25 Critical iOS, iPadOS, and macOS Vulnerabilities in July 2026 Disclosure

Apple released a major security update on July 27, 2026, patching 25 vulnerabilities across its operating systems, including critical flaws allowing kernel code execution and sandbox escapes.

Key findings

  • Apple patched 25 vulnerabilities across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS on July 27, 2026.
  • Critical flaws include memory corruption, sandbox escapes, and potential for kernel code execution.
  • Vulnerabilities addressed by improved memory management, input validation, and bounds checking.
  • Affected systems updated to iOS 26.6 and corresponding OS versions, including macOS Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6.
  • No active exploitation reported by Apple at the time of disclosure.

On July 27, 2026, Apple released a significant security update addressing a batch of 25 vulnerabilities across its iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems. The vulnerabilities, disclosed on the same day, span a range of issues including memory corruption, sandbox escapes, and unauthorized data access. The fixes are available in iOS 26.6, iPadOS 26.6, macOS Tahoe 26.6, and other corresponding OS versions. Apple did not report any active exploitation of these vulnerabilities at the time of disclosure.

Several critical vulnerabilities were patched, including memory initialization issues (CVE-2026-64775), integer overflows (CVE-2026-64774), and out-of-bounds writes (CVE-2026-64772, CVE-2026-64770, CVE-2026-64769), all with a CVSS score of 9.8. These flaws could lead to unexpected system termination or heap corruption. Additionally, a parsing issue in directory path handling (CVE-2026-64740) with a CVSS score of 9.3 could allow a malicious app to break out of its sandbox.

Other high-severity vulnerabilities include use-after-free issues (CVE-2026-64783, CVE-2026-64751), buffer overflows (CVE-2026-64747), and out-of-bounds reads (CVE-2026-64768). These could result in unexpected application termination, kernel memory corruption, or even arbitrary code execution with kernel privileges. Several of these high-severity flaws were addressed by improved memory management, input validation, and bounds checking.

Medium-severity vulnerabilities were also addressed, including authorization issues (CVE-2026-64755, CVE-2026-64743, CVE-2026-64746, CVE-2026-64742) that could lead to unauthorized data access or the addition of contacts without user permission. A permissions issue (CVE-2026-64741) could allow an app to read a persistent device identifier.

The updates were released for iOS 26.6 and iPadOS 26.6, along with corresponding updates for macOS, tvOS, visionOS, and watchOS. Specifically, macOS Sequoia received version 15.7.8, macOS Sonoma received version 14.8.8, and macOS Tahoe received version 26.6. Safari also received an update to version 26.6.

These patches are crucial for users of all affected Apple devices, as they address critical flaws that could compromise system stability, data security, and user privacy. Users are strongly advised to update their devices to the latest available versions to mitigate these risks. The broad range of vulnerabilities patched highlights the importance of regular security updates for maintaining the integrity of the Apple ecosystem.

AI-written article. Grounded in 25 CVE records listed below.