Multiple vulnerabilities in Apple products (July 28, 2026)
Multiple vulnerabilities have been discovered in Apple products. Some of them allow an attacker to cause arbitrary code execution, privilege escalation, and a breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Apple products can lead to arbitrary code execution, privilege escalation, and information disclosure.
- Who is affected
- Users of affected Apple products are at risk from these vulnerabilities.
- Urgency
- This is an urgent situation as exploitation could lead to severe security issues.
- Action
- Users should update their Apple products to the latest versions to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0938/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-437300.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-647340.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-289820.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-437660.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-438040.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-437380.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-436940.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-438110.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-437990.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-437550.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- unknownApple Products Multiple Vulnerabilitieshkcert
- criticalCVE-2026-64774: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 2…nvd
- criticalCVE-2026-64770: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed …nvd
- highCVE-2026-64765: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 2…nvd
- highCVE-2026-64763: An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixe…nvd
- criticalCVE-2026-64762: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macO…nvd
Recent advisories for Apple products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-28
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-06
- unknownMultiple vulnerabilities in Apple products (June 30, 2026)cert-fr-avis · 2026-06-30
- criticalexploitedCVE-2025-31277: Apple Multiple Products Buffer Overflow Vulnerabilitycisa-kev · 2026-03-20
- criticalexploitedCVE-2025-43520: Apple Multiple Products Classic Buffer Overflow Vulnerabilitycisa-kev · 2026-03-20
- criticalexploitedCVE-2025-43510: Apple Multiple Products Improper Locking Vulnerabilitycisa-kev · 2026-03-20
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31