DIRAS TAKE
Urgent: the flaw requires no authentication or user interaction and is fixed in 26.6; apply the vendor updates promptly to remove remote crash risk.
What is CVE-2026-64720?
An unauthenticated remote attacker can cause unexpected system termination on Apple iOS and iPadOS (CVE-2026-64720). The issue affects iOS and iPadOS 26.x releases before 26.6 and similar builds of macOS, tvOS, and watchOS listed by Apple; it was fixed in 26.6. According to the vendor-provided details and the CVSS vector, exploitation requires no privileges and no user interaction, meaning network access to a vulnerable device is sufficient for an attack that can crash the system.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64720 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64720
- Upgrade affected devices to iOS/iPadOS 26.6 (and macOS/tvOS/watchOS 26.6 where applicable).
- Follow Apple’s update guidance and install the security release on all managed devices immediately.
- Restrict network exposure of vulnerable devices until patches are deployed.
- Monitor device logs and crash reports for unexplained system terminations.
Frequently asked questions
Is CVE-2026-64720 being actively exploited?
There are no public reports of exploitation of CVE-2026-64720 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64720?
iOS and iPadOS 26.x releases before 26.6 are affected; Apple also lists macOS, tvOS, and watchOS 26.x builds before 26.6 as vulnerable.
Is there a patch for CVE-2026-64720?
Yes. Apple fixed the issue in 26.6 for iOS, iPadOS, macOS, tvOS, and watchOS; apply those updates to remediate.
Does CVE-2026-64720 require authentication?
No. The reported vulnerability requires no privileges and no user interaction, so authentication is not required to trigger the issue.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64720
- cve.org/CVERecord?id=CVE-2026-64720
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- All Apple CVEs on CVE Radar
- CVEs published in September 2026