VYPR
Vypr IntelligenceAI-generatedJul 27, 2026· 25 CVEs

Apple watchOS: 25 Vulnerabilities Patched in Same-Day July 2026 Disclosure

Apple released a significant security update on July 27, 2026, patching 25 vulnerabilities across its operating systems, including watchOS, with critical flaws enabling code execution and data access.

Key findings

  • Apple patched 25 vulnerabilities across its operating systems on July 27, 2026, including watchOS.
  • Critical flaws (up to CVSS 9.8) involved memory corruption, integer overflows, and out-of-bounds writes.
  • Several vulnerabilities could lead to arbitrary code execution, kernel-level access, or unexpected system termination.
  • Authorization flaws allowed unauthorized contact addition and sensitive data access.
  • All affected systems were updated to version 26.6 or equivalent, with no reported active exploitation.

On July 27, 2026, Apple Inc. released a significant security update addressing a batch of 25 vulnerabilities across its iOS, iPadOS, macOS, tvOS, visionOS, and watchOS operating systems, including watchOS. The vulnerabilities, disclosed on the same day, span a range of issues including memory corruption, sandbox escapes, and unauthorized data access. These vulnerabilities, if exploited, could lead to unexpected system termination, kernel memory corruption, or arbitrary code execution.

Several vulnerabilities were related to memory management and input validation. CVE-2026-64775, CVE-2026-64751, and CVE-2026-64720, all rated Critical, involved use-after-free or memory initialization issues that could lead to unexpected system termination or kernel memory corruption. CVE-2026-64766, CVE-2026-64765, and CVE-2026-64764, all rated High, stemmed from integer overflows or out-of-bounds writes, potentially leading to app termination or arbitrary code execution. CVE-2026-64758 and CVE-2026-64783, also High severity, were use-after-free issues in Safari that could cause unexpected crashes.

Other vulnerabilities addressed included authorization flaws and data handling issues. CVE-2026-64746, a Critical vulnerability, allowed an app to add contacts without user authorization. CVE-2026-64733, also Critical, could enable an app to fingerprint the user through improved data protection. Medium severity issues like CVE-2026-64743 and CVE-2026-64742 involved authorization problems that could lead to sensitive user data access, with CVE-2026-64742 specifically addressed by enforcing HTTPS for data transmission.

Apple addressed these vulnerabilities with improved memory management, input validation, and bounds checking. All affected systems were updated to iOS 26.6 and corresponding OS versions, including watchOS 26.6. For macOS, updates were released for Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6.

While Apple did not report any active exploitation of these vulnerabilities at the time of disclosure, the sheer volume and severity of the flaws underscore the importance of timely updates. Users of Apple devices, including those running watchOS, should ensure their systems are updated to the latest versions to mitigate risks associated with memory corruption, arbitrary code execution, and unauthorized data access. The batch of 25 vulnerabilities highlights a broad security focus across Apple's ecosystem, with fixes distributed across multiple operating systems and core components.

AI-written article. Grounded in 25 CVE records listed below.