• PATCH AVAILABLE

CVE-2026-64726: pre-auth memory corruption in Apple iOS and iPadOS

An unauthenticated attacker can trigger memory corruption in Apple iOS and iPadOS and achieve remote code execution; this is tracked as CVE-2026-64726. The flaw affects iOS and iPadOS before 18.7.10 and before 26.6, and related Apple platforms listed below also have fixes. According to the CVSS vector the issue is exploitable over the network without privileges or user interaction, so an attacker only needs network access to a vulnerable device to attempt exploitation.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0065
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth, network-exploitable memory corruption that can lead to remote code execution; apply Apple's available updates immediately to affected devices.

What is CVE-2026-64726?

An unauthenticated attacker can trigger memory corruption in Apple iOS and iPadOS and achieve remote code execution; this is tracked as CVE-2026-64726. The flaw affects iOS and iPadOS before 18.7.10 and before 26.6, and related Apple platforms listed below also have fixes. According to the CVSS vector the issue is exploitable over the network without privileges or user interaction, so an attacker only needs network access to a vulnerable device to attempt exploitation.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64726 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64726

  1. Install vendor updates: update to iOS/iPadOS 18.7.10 or 26.6, and to macOS/tvOS/visionOS/watchOS 26.6 where applicable.
  2. If you cannot patch immediately, restrict network exposure of vulnerable devices from untrusted networks and services.
  3. Monitor device logs and network traffic for unusual connections or crashes and follow Apple security guidance.

Frequently asked questions

Is CVE-2026-64726 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64726?

iOS and iPadOS releases before 18.7.10 and before 26.6 are listed as affected; related Apple platforms also have fixes in 26.6.

Is there a patch for CVE-2026-64726?

Yes. Apple released fixes in iOS and iPadOS 18.7.10 and 26.6, and in macOS/tvOS/visionOS/watchOS 26.6.

Does CVE-2026-64726 require authentication?

No. The vulnerability is exploitable without privileges or user interaction and can be reached over the network.

References