DIRAS TAKE
Treat this as high priority: Apple published fixes for the affected releases and devices should be updated to the listed fixed versions immediately to remove the sandbox escape vector.
What is CVE-2026-64738?
A malicious app can break out of the app sandbox on iOS, iPadOS and several macOS releases, allowing a local app to perform actions beyond its intended permissions. This is tracked as CVE-2026-64738. Affected releases include iOS and iPadOS 18.x before 18.7.10 and multiple macOS branches (macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, macOS 26.x before 26.6). Exploitation requires a malicious app running on the device; no network access or user interaction is specified in the available facts.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64738 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64738
- Update iPhone or iPad to iOS/iPadOS 18.7.10 or later.
- Update macOS to the fixed releases (macOS 14.8.8, 15.7.8, or 26.6 as applicable).
- Restrict installation of untrusted or sideloaded apps and review mobile device management policies; monitor devices for anomalous app behavior.
Frequently asked questions
Is CVE-2026-64738 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64738?
iOS and iPadOS 18.x releases before 18.7.10 are affected; updating to 18.7.10 removes the vulnerability for those branches.
Is there a patch for CVE-2026-64738?
Yes. Apple released fixes: iOS and iPadOS 18.7.10 and macOS fixes in 14.8.8, 15.7.8, and 26.6 address the issue.
What can an attacker do with CVE-2026-64738?
A malicious app on an affected iOS, iPadOS or macOS device may be able to escape its sandbox and perform actions beyond its normal permissions.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64738
- cve.org/CVERecord?id=CVE-2026-64738
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026