• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-64725: out-of-bounds write in Apple iOS and iPadOS

A local app can trigger an out-of-bounds write that may crash iOS and iPadOS devices (denial-of-service). CVE-2026-64725 affects iOS and iPadOS releases before 18.7.10 and before 26.6; related fixes are also available for macOS, tvOS, visionOS and watchOS branches. An attacker needs to run a malicious or compromised app on the device and may require a user to install or run that app. The issue was corrected with improved bounds checking in vendor updates.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.1HIGH
EPSS
0.00164
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so apply Apple’s security updates immediately for affected platforms or otherwise restrict untrusted app installs and monitor device stability.

What is CVE-2026-64725?

A local app can trigger an out-of-bounds write that may crash iOS and iPadOS devices (denial-of-service). CVE-2026-64725 affects iOS and iPadOS releases before 18.7.10 and before 26.6; related fixes are also available for macOS, tvOS, visionOS and watchOS branches. An attacker needs to run a malicious or compromised app on the device and may require a user to install or run that app. The issue was corrected with improved bounds checking in vendor updates. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64725 being exploited?

Public exploit code is available.

How to fix CVE-2026-64725

  1. Install Apple’s security updates: update iOS/iPadOS to 18.7.10 or 26.6 as appropriate.
  2. Update other Apple platforms to the listed fixes (macOS 14.8.8, 15.7.8, and 26.6; tvOS/visionOS/watchOS 26.6).
  3. Restrict installation of untrusted or sideloaded apps and enforce mobile device management controls.
  4. Monitor devices for crashes or unexplained reboots and review app installations for suspicious or unapproved software.

Frequently asked questions

Is CVE-2026-64725 being actively exploited?

Public exploit code for CVE-2026-64725 is available.

Which iOS and iPadOS versions are affected by CVE-2026-64725?

iOS and iPadOS releases prior to 18.7.10 and prior to 26.6 are affected; related fixes exist for other Apple platform branches.

Is there a patch for CVE-2026-64725?

Yes. Apple released fixes including iOS/iPadOS 18.7.10 and 26.6 and updates for macOS, tvOS, visionOS and watchOS as listed by the vendor.

Does CVE-2026-64725 require authentication?

No authentication is required beyond running an app on the device; the issue involves a local app triggering an out-of-bounds write.

References