CVE-2026-64705Medium· 5.5▾ TwilightPoC availableA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or wri…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 30.3 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
0.1% → 0.1%
1 GitHub repo (last check)
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.
macos >= 14.0, < 14.8.7macos >= 15.0, < 15.7.7Upgrade past the affected range:
macos 15.7.7Connected by shared product, vendor, weakness, or advisory.
CVE-2026-43748Critical· 9.8An out-of-bounds write issue was addressed with improved bounds checking
CVE-2026-43783High· 7.8A race condition was addressed with improved locking
CVE-2026-43760High· 8.6An access issue was addressed with improved access restrictions
CVE-2026-28934Medium· 6.5A buffer overflow was addressed with improved bounds checking
CVE-2026-43763Medium· 5.5A permissions issue was addressed by removing the vulnerable code
CVE-2026-84520Critical· 9.8A buffer overflow was addressed with improved size validation