• PATCH AVAILABLE

CVE-2026-64733: information disclosure in Apple iOS and iPadOS

An attacker can fingerprint users of Apple iOS and iPadOS apps to obtain sensitive device or user-identifying data; this is tracked as CVE-2026-64733. The issue affects iOS and iPadOS 26.x releases before 26.6 (also macOS, tvOS, visionOS, and watchOS 26.x before 26.6). Exploitation requires only network access to an affected device through an app or service and does not require user interaction or an authenticated session.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00605
CWE
CWE-200
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is rated critical with network, no-auth, no-UI attack vectors (CVSS 9.8), so prioritize deploying the vendor fix 26.6 immediately for internet-facing and high-risk devices.

What is CVE-2026-64733?

An attacker can fingerprint users of Apple iOS and iPadOS apps to obtain sensitive device or user-identifying data; this is tracked as CVE-2026-64733. The issue affects iOS and iPadOS 26.x releases before 26.6 (also macOS, tvOS, visionOS, and watchOS 26.x before 26.6). Exploitation requires only network access to an affected device through an app or service and does not require user interaction or an authenticated session. The weakness is classified as CWE-200 (Exposure of Sensitive Information).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64733 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64733

  1. Install the vendor updates that fix this issue: update to 26.6 on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
  2. Restrict network exposure for affected devices and limit access to untrusted networks until patches are applied.
  3. Monitor network and application logs for unusual fingerprinting or probing activity from unknown sources.
  4. Follow Apple's security guidance for updating managed fleets and block unpatched devices from sensitive resources.

Frequently asked questions

Is CVE-2026-64733 being actively exploited?

There are no public reports of exploitation of CVE-2026-64733 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64733?

iOS and iPadOS 26.x releases before 26.6 are affected; the same pre-26.6 range applies to macOS, tvOS, visionOS, and watchOS 26.x.

Is there a patch for CVE-2026-64733?

Yes. Apple released fixes in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.

Does CVE-2026-64733 require authentication?

No. The vulnerability can be exploited without authentication or user interaction against affected Apple operating system versions.

References