• PATCH AVAILABLE

CVE-2026-64729: use-after-free in Apple iOS and iPadOS

A locally-run app can trigger a use-after-free vulnerability to cause unexpected system termination or potentially worse on Apple platforms; this is tracked as CVE-2026-64729. The issue affects iOS and iPadOS 26.x before 26.6 and also macOS, tvOS, visionOS and watchOS 26.x releases before 26.6. An attacker needs the ability to run a crafted app on the target device; no additional privileges or user interaction are indicated in the reported data.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00588
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is rated critical (CVSS 9.8) and Apple released fixes in 26.6 for all affected branches — apply the 26.6 updates promptly to remove the vulnerability.

What is CVE-2026-64729?

A locally-run app can trigger a use-after-free vulnerability to cause unexpected system termination or potentially worse on Apple platforms; this is tracked as CVE-2026-64729. The issue affects iOS and iPadOS 26.x before 26.6 and also macOS, tvOS, visionOS and watchOS 26.x releases before 26.6. An attacker needs the ability to run a crafted app on the target device; no additional privileges or user interaction are indicated in the reported data. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64729 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64729

  1. Install the vendor fixes: upgrade iOS/iPadOS, macOS, tvOS, visionOS and watchOS 26.x to 26.6.
  2. Remove or block untrusted apps and restrict app install sources until devices are patched.
  3. Monitor devices for unexpected terminations and crashes and investigate any apps that reproduce the issue.
  4. Follow Apple’s security guidance and update device management policies to enforce the 26.6 update.

Frequently asked questions

Is CVE-2026-64729 being actively exploited?

There are no public reports of exploitation of CVE-2026-64729 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64729?

iOS and iPadOS 26.x releases before 26.6 are affected; the same fixed version number (26.6) applies to the related Apple platforms listed in the advisory.

Is there a patch for CVE-2026-64729?

Yes. Apple fixed the issue in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS and watchOS 26.x.

Does CVE-2026-64729 require authentication?

The reported data indicates no privileges or user interaction are required, so the issue can be triggered without prior authentication on the affected Apple platforms.

References