• PATCH AVAILABLE

CVE-2026-64720: race condition in Apple iOS and iPadOS

An unauthenticated remote attacker can cause unexpected system termination on Apple iOS and iPadOS (CVE-2026-64720). The issue affects iOS and iPadOS 26.x releases before 26.6 and similar builds of macOS, tvOS, and watchOS listed by Apple; it was fixed in 26.6. According to the vendor-provided details and the CVSS vector, exploitation requires no privileges and no user interaction, meaning network access to a vulnerable device is sufficient for an attack that can crash the system.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00467
CWE
CWE-362
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: the flaw requires no authentication or user interaction and is fixed in 26.6; apply the vendor updates promptly to remove remote crash risk.

What is CVE-2026-64720?

An unauthenticated remote attacker can cause unexpected system termination on Apple iOS and iPadOS (CVE-2026-64720). The issue affects iOS and iPadOS 26.x releases before 26.6 and similar builds of macOS, tvOS, and watchOS listed by Apple; it was fixed in 26.6. According to the vendor-provided details and the CVSS vector, exploitation requires no privileges and no user interaction, meaning network access to a vulnerable device is sufficient for an attack that can crash the system.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64720 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64720

  1. Upgrade affected devices to iOS/iPadOS 26.6 (and macOS/tvOS/watchOS 26.6 where applicable).
  2. Follow Apple’s update guidance and install the security release on all managed devices immediately.
  3. Restrict network exposure of vulnerable devices until patches are deployed.
  4. Monitor device logs and crash reports for unexplained system terminations.

Frequently asked questions

Is CVE-2026-64720 being actively exploited?

There are no public reports of exploitation of CVE-2026-64720 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64720?

iOS and iPadOS 26.x releases before 26.6 are affected; Apple also lists macOS, tvOS, and watchOS 26.x builds before 26.6 as vulnerable.

Is there a patch for CVE-2026-64720?

Yes. Apple fixed the issue in 26.6 for iOS, iPadOS, macOS, tvOS, and watchOS; apply those updates to remediate.

Does CVE-2026-64720 require authentication?

No. The reported vulnerability requires no privileges and no user interaction, so authentication is not required to trigger the issue.

References