DIRAS TAKE
Urgent: this is rated critical (CVSS 9.8) and Apple released fixes in 26.6 for all affected branches — apply the 26.6 updates promptly to remove the vulnerability.
What is CVE-2026-64729?
A locally-run app can trigger a use-after-free vulnerability to cause unexpected system termination or potentially worse on Apple platforms; this is tracked as CVE-2026-64729. The issue affects iOS and iPadOS 26.x before 26.6 and also macOS, tvOS, visionOS and watchOS 26.x releases before 26.6. An attacker needs the ability to run a crafted app on the target device; no additional privileges or user interaction are indicated in the reported data. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64729 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64729
- Install the vendor fixes: upgrade iOS/iPadOS, macOS, tvOS, visionOS and watchOS 26.x to 26.6.
- Remove or block untrusted apps and restrict app install sources until devices are patched.
- Monitor devices for unexpected terminations and crashes and investigate any apps that reproduce the issue.
- Follow Apple’s security guidance and update device management policies to enforce the 26.6 update.
Frequently asked questions
Is CVE-2026-64729 being actively exploited?
There are no public reports of exploitation of CVE-2026-64729 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64729?
iOS and iPadOS 26.x releases before 26.6 are affected; the same fixed version number (26.6) applies to the related Apple platforms listed in the advisory.
Is there a patch for CVE-2026-64729?
Yes. Apple fixed the issue in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS and watchOS 26.x.
Does CVE-2026-64729 require authentication?
The reported data indicates no privileges or user interaction are required, so the issue can be triggered without prior authentication on the affected Apple platforms.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64729
- cve.org/CVERecord?id=CVE-2026-64729
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- All Apple CVEs on CVE Radar
- CVEs published in September 2026