• PATCH AVAILABLE

CVE-2026-64700: use-after-free in Apple iOS and iPadOS

A malicious app can cause unexpected system termination on Apple platforms; CVE-2026-64700. The issue affects iOS and iPadOS (before 18.7.10 and before 26.6) and also macOS, tvOS, visionOS and watchOS releases listed below. An attacker needs a local app running on the device (the vulnerability is triggered by an app) rather than remote network access or user interaction beyond running the app.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00661
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: install the vendor fixes because Apple has released patched builds for each affected branch (for example iOS/iPadOS 18.7.10 and 26.6). Applying those updates closes the reported use-after-free memory bug.

What is CVE-2026-64700?

A malicious app can cause unexpected system termination on Apple platforms; CVE-2026-64700. The issue affects iOS and iPadOS (before 18.7.10 and before 26.6) and also macOS, tvOS, visionOS and watchOS releases listed below. An attacker needs a local app running on the device (the vulnerability is triggered by an app) rather than remote network access or user interaction beyond running the app. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64700 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64700

  1. Install the vendor updates: iOS/iPadOS 18.7.10 or 26.6, macOS 14.8.8, 15.7.8, or 26.6, and tvOS/visionOS/watchOS 26.6 as applicable.
  2. If you cannot update immediately, restrict which apps can be installed and run on devices and enforce app-vetting or MDM policies.
  3. Monitor device crash logs and telemetry for unexpected system terminations and anomalous app behavior.
  4. Follow Apple’s security advisory and apply additional vendor guidance where provided.

Frequently asked questions

Is CVE-2026-64700 being actively exploited?

There are no public reports of exploitation of CVE-2026-64700 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64700?

iOS and iPadOS releases before 18.7.10 and before 26.6 are listed as affected by CVE-2026-64700.

Is there a patch for CVE-2026-64700?

Yes. Apple published fixes: iOS and iPadOS 18.7.10 and 26.6, and corresponding updates for macOS, tvOS, visionOS and watchOS as listed in the vendor advisories.

Does CVE-2026-64700 require authentication?

No authentication is required beyond running an app; the vulnerability is triggered by an app running on the affected Apple platform.

References