DIRAS TAKE
Urgent: public exploit code exists, so apply Apple’s security updates immediately for affected platforms or otherwise restrict untrusted app installs and monitor device stability.
What is CVE-2026-64725?
A local app can trigger an out-of-bounds write that may crash iOS and iPadOS devices (denial-of-service). CVE-2026-64725 affects iOS and iPadOS releases before 18.7.10 and before 26.6; related fixes are also available for macOS, tvOS, visionOS and watchOS branches. An attacker needs to run a malicious or compromised app on the device and may require a user to install or run that app. The issue was corrected with improved bounds checking in vendor updates. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64725 being exploited?
Public exploit code is available.
How to fix CVE-2026-64725
- Install Apple’s security updates: update iOS/iPadOS to 18.7.10 or 26.6 as appropriate.
- Update other Apple platforms to the listed fixes (macOS 14.8.8, 15.7.8, and 26.6; tvOS/visionOS/watchOS 26.6).
- Restrict installation of untrusted or sideloaded apps and enforce mobile device management controls.
- Monitor devices for crashes or unexplained reboots and review app installations for suspicious or unapproved software.
Frequently asked questions
Is CVE-2026-64725 being actively exploited?
Public exploit code for CVE-2026-64725 is available.
Which iOS and iPadOS versions are affected by CVE-2026-64725?
iOS and iPadOS releases prior to 18.7.10 and prior to 26.6 are affected; related fixes exist for other Apple platform branches.
Is there a patch for CVE-2026-64725?
Yes. Apple released fixes including iOS/iPadOS 18.7.10 and 26.6 and updates for macOS, tvOS, visionOS and watchOS as listed by the vendor.
Does CVE-2026-64725 require authentication?
No authentication is required beyond running an app on the device; the issue involves a local app triggering an out-of-bounds write.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64725
- cve.org/CVERecord?id=CVE-2026-64725
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026