• PATCH AVAILABLE

CVE-2026-64738: sandbox escape in Apple iOS and iPadOS

A malicious app can break out of the app sandbox on iOS, iPadOS and several macOS releases, allowing a local app to perform actions beyond its intended permissions. This is tracked as CVE-2026-64738. Affected releases include iOS and iPadOS 18.x before 18.7.10 and multiple macOS branches (macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, macOS 26.x before 26.6). Exploitation requires a malicious app running on the device; no network access or user interaction is specified in the available facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0056
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority: Apple published fixes for the affected releases and devices should be updated to the listed fixed versions immediately to remove the sandbox escape vector.

What is CVE-2026-64738?

A malicious app can break out of the app sandbox on iOS, iPadOS and several macOS releases, allowing a local app to perform actions beyond its intended permissions. This is tracked as CVE-2026-64738. Affected releases include iOS and iPadOS 18.x before 18.7.10 and multiple macOS branches (macOS 14.x before 14.8.8, macOS 15.x before 15.7.8, macOS 26.x before 26.6). Exploitation requires a malicious app running on the device; no network access or user interaction is specified in the available facts.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6

Is CVE-2026-64738 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64738

  1. Update iPhone or iPad to iOS/iPadOS 18.7.10 or later.
  2. Update macOS to the fixed releases (macOS 14.8.8, 15.7.8, or 26.6 as applicable).
  3. Restrict installation of untrusted or sideloaded apps and review mobile device management policies; monitor devices for anomalous app behavior.

Frequently asked questions

Is CVE-2026-64738 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64738?

iOS and iPadOS 18.x releases before 18.7.10 are affected; updating to 18.7.10 removes the vulnerability for those branches.

Is there a patch for CVE-2026-64738?

Yes. Apple released fixes: iOS and iPadOS 18.7.10 and macOS fixes in 14.8.8, 15.7.8, and 26.6 address the issue.

What can an attacker do with CVE-2026-64738?

A malicious app on an affected iOS, iPadOS or macOS device may be able to escape its sandbox and perform actions beyond its normal permissions.

References