VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

Apple visionOS: 25 Vulnerabilities Patched in Same-Day July 2026 Disclosure

Apple disclosed 25 vulnerabilities affecting visionOS and other operating systems on July 27, 2026, ranging from critical memory corruption to authorization bypasses.

Key findings

  • Apple patched 25 vulnerabilities across its operating systems on July 27, 2026, including visionOS.
  • Critical flaws (up to CVSS 9.8) involved memory corruption, integer overflows, and out-of-bounds writes.
  • Several vulnerabilities could lead to arbitrary code execution or kernel-level access.
  • Authorization flaws allowed unauthorized contact addition and sensitive data access.
  • All affected systems were updated to version 26.6 or equivalent, with no reported active exploitation.

On July 27, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities across its iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems. The vulnerabilities, disclosed on the same day, span a range of issues including memory corruption, sandbox escapes, and unauthorized data access.

Several critical vulnerabilities were patched, including memory initialization issues (CVE-2026-64775), integer overflows (CVE-2026-64774), out-of-bounds writes (CVE-2026-64772, CVE-2026-64770, CVE-2026-64769), and buffer overflows (CVE-2026-64771). These flaws, with CVSS scores up to 9.8, could allow remote attackers to cause unexpected application termination or heap corruption.

Other high-severity vulnerabilities addressed include use-after-free issues (CVE-2026-64783), out-of-bounds reads (CVE-2026-64768), integer overflows leading to potential arbitrary code execution (CVE-2026-64766, CVE-2026-64765), and out-of-bounds writes with similar potential impacts (CVE-2026-64764, CVE-2026-64763). Additionally, a use-after-free issue (CVE-2026-64751) could lead to unexpected system termination or kernel memory writes, and a buffer overflow (CVE-2026-64747) could enable arbitrary code execution with kernel privileges.

Authorization issues were also part of this disclosure, with CVE-2026-64746 allowing an app to add contacts without user authorization, and CVE-2026-64743 enabling access to sensitive user data. CVE-2026-64742 addresses an issue where an app could access sensitive user data by not using HTTPS for network information transfer. A UI inconsistency (CVE-2026-64735) could allow a remote attacker to bypass network filters, and CVE-2026-64734 could leak sensitive data when processing a maliciously crafted contact. Finally, CVE-2026-64733, a critical vulnerability, could allow an app to fingerprint the user.

Apple has addressed these vulnerabilities with improved memory management, input validation, bounds checking, state management, and data protection. The fixes are available in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, and watchOS 26.6. While Apple did not report any active exploitation of these CVEs at the time of disclosure, the sheer number and severity of the patched vulnerabilities underscore the importance of applying these updates promptly.

Users of Apple devices are strongly advised to update their systems to the latest versions to mitigate the risks associated with these memory corruption, authorization, and other critical vulnerabilities. The comprehensive nature of this patch batch highlights Apple's ongoing efforts to secure its ecosystem against a wide range of potential threats.

CVE-2026-64783, CVE-2026-64775, CVE-2026-64774, CVE-2026-64772, CVE-2026-64771, CVE-2026-64770, CVE-2026-64769, CVE-2026-64768, CVE-2026-64766, CVE-2026-64765, CVE-2026-64764, CVE-2026-64763, CVE-2026-64758, CVE-2026-64757, CVE-2026-64754, CVE-2026-64751, CVE-2026-64749, CVE-2026-64747, CVE-2026-64746, CVE-2026-64743, CVE-2026-64742, CVE-2026-64739, CVE-2026-64735, CVE-2026-64734, CVE-2026-64733.

AI-written article. Grounded in 25 CVE records listed below.