DIRAS TAKE
High urgency — the bug can be reached over the network without credentials, so prioritize installing the vendor updates (for example iOS/iPadOS 18.7.10) on exposed devices immediately.
What is CVE-2026-64695?
Remote actors can trigger kernel memory corruption or force unexpected device crashes on Apple iOS, iPadOS and supported macOS releases; this issue is tracked as CVE-2026-64695. Affected releases include iOS and iPadOS 18.x prior to 18.7.10 and several macOS branches before their listed fixes. Exploitation requires only network access and does not need an authenticated account or user interaction, so any reachable device running an affected version could be targeted remotely.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64695 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64695
- Install Apple’s security updates: upgrade iOS/iPadOS to 18.7.10 and macOS to the indicated fixed releases (14.8.8, 15.7.8, 26.6).
- Temporarily reduce network exposure for affected devices by blocking unnecessary inbound traffic and limiting services to trusted networks.
- Monitor device crash logs and kernel panic reports for patterns of unexpected terminations or memory corruption.
- Follow vendor guidance and use centralized update management to ensure all endpoints receive the fixes.
Frequently asked questions
Is CVE-2026-64695 being actively exploited?
There are no public reports of active exploitation of CVE-2026-64695 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64695?
iOS and iPadOS 18.x releases before 18.7.10 are affected by CVE-2026-64695.
Is there a patch for CVE-2026-64695?
Yes. Apple provided fixes; affected devices should be updated to iOS/iPadOS 18.7.10 and the listed macOS fixed releases.
Does CVE-2026-64695 require authentication?
No. The vulnerability can be triggered without authentication or user interaction, provided the attacker can reach the device over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64695
- cve.org/CVERecord?id=CVE-2026-64695
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026