DIRAS TAKE
Urgent: this is rated critical with network, no-auth, no-UI attack vectors (CVSS 9.8), so prioritize deploying the vendor fix 26.6 immediately for internet-facing and high-risk devices.
What is CVE-2026-64733?
An attacker can fingerprint users of Apple iOS and iPadOS apps to obtain sensitive device or user-identifying data; this is tracked as CVE-2026-64733. The issue affects iOS and iPadOS 26.x releases before 26.6 (also macOS, tvOS, visionOS, and watchOS 26.x before 26.6). Exploitation requires only network access to an affected device through an app or service and does not require user interaction or an authenticated session. The weakness is classified as CWE-200 (Exposure of Sensitive Information).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64733 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64733
- Install the vendor updates that fix this issue: update to 26.6 on iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
- Restrict network exposure for affected devices and limit access to untrusted networks until patches are applied.
- Monitor network and application logs for unusual fingerprinting or probing activity from unknown sources.
- Follow Apple's security guidance for updating managed fleets and block unpatched devices from sensitive resources.
Frequently asked questions
Is CVE-2026-64733 being actively exploited?
There are no public reports of exploitation of CVE-2026-64733 as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64733?
iOS and iPadOS 26.x releases before 26.6 are affected; the same pre-26.6 range applies to macOS, tvOS, visionOS, and watchOS 26.x.
Is there a patch for CVE-2026-64733?
Yes. Apple released fixes in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Does CVE-2026-64733 require authentication?
No. The vulnerability can be exploited without authentication or user interaction against affected Apple operating system versions.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64733
- cve.org/CVERecord?id=CVE-2026-64733
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- All Apple CVEs on CVE Radar
- CVEs published in September 2026