• PATCH AVAILABLE

CVE-2026-64695: memory corruption in Apple iOS and iPadOS

Remote actors can trigger kernel memory corruption or force unexpected device crashes on Apple iOS, iPadOS and supported macOS releases; this issue is tracked as CVE-2026-64695. Affected releases include iOS and iPadOS 18.x prior to 18.7.10 and several macOS branches before their listed fixes. Exploitation requires only network access and does not need an authenticated account or user interaction, so any reachable device running an affected version could be targeted remotely.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00729
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

High urgency — the bug can be reached over the network without credentials, so prioritize installing the vendor updates (for example iOS/iPadOS 18.7.10) on exposed devices immediately.

What is CVE-2026-64695?

Remote actors can trigger kernel memory corruption or force unexpected device crashes on Apple iOS, iPadOS and supported macOS releases; this issue is tracked as CVE-2026-64695. Affected releases include iOS and iPadOS 18.x prior to 18.7.10 and several macOS branches before their listed fixes. Exploitation requires only network access and does not need an authenticated account or user interaction, so any reachable device running an affected version could be targeted remotely.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6

Is CVE-2026-64695 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64695

  1. Install Apple’s security updates: upgrade iOS/iPadOS to 18.7.10 and macOS to the indicated fixed releases (14.8.8, 15.7.8, 26.6).
  2. Temporarily reduce network exposure for affected devices by blocking unnecessary inbound traffic and limiting services to trusted networks.
  3. Monitor device crash logs and kernel panic reports for patterns of unexpected terminations or memory corruption.
  4. Follow vendor guidance and use centralized update management to ensure all endpoints receive the fixes.

Frequently asked questions

Is CVE-2026-64695 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64695 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64695?

iOS and iPadOS 18.x releases before 18.7.10 are affected by CVE-2026-64695.

Is there a patch for CVE-2026-64695?

Yes. Apple provided fixes; affected devices should be updated to iOS/iPadOS 18.7.10 and the listed macOS fixed releases.

Does CVE-2026-64695 require authentication?

No. The vulnerability can be triggered without authentication or user interaction, provided the attacker can reach the device over the network.

References