• PATCH AVAILABLE

CVE-2026-64746: authorization bypass in Apple iOS and iPadOS

A malicious or buggy app can add contacts to an iOS or iPadOS device without the user granting permission. CVE-2026-64746 is an authorization validation flaw that affects iOS and iPadOS releases before the vendor fixes. Affected releases include iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6; related fixes are also available for macOS, visionOS and watchOS. Exploitation requires an app on the device and does not require user interaction to succeed according to the reported vulnerability details.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0056
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — Apple shipped fixes (18.7.10 and 26.6) because an installed app can modify contacts without consent; update devices running affected releases immediately or block installation of untrusted apps until patched.

What is CVE-2026-64746?

A malicious or buggy app can add contacts to an iOS or iPadOS device without the user granting permission. CVE-2026-64746 is an authorization validation flaw that affects iOS and iPadOS releases before the vendor fixes. Affected releases include iOS and iPadOS 18.x before 18.7.10 and 26.x before 26.6; related fixes are also available for macOS, visionOS and watchOS. Exploitation requires an app on the device and does not require user interaction to succeed according to the reported vulnerability details.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64746 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64746

  1. Install Apple’s updates: upgrade iOS/iPadOS 18.x to 18.7.10 or later and 26.x to 26.6 or later; apply corresponding macOS, visionOS and watchOS updates.
  2. Prevent installation of untrusted apps and restrict device app sources until devices are patched.
  3. Monitor device and MDM logs for unexpected contact additions and audit apps that request contacts access.
  4. Follow vendor guidance and apply configuration controls from your mobile device management solution.

Frequently asked questions

Is CVE-2026-64746 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64746 as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64746?

iOS and iPadOS releases before 18.7.10 (18.x) and before 26.6 (26.x) are listed as affected; related fixes were also issued for macOS, visionOS and watchOS.

Is there a patch for CVE-2026-64746?

Yes. Apple fixed the issue in iOS and iPadOS 18.7.10 and in 26.6; corresponding updates exist for macOS, visionOS and watchOS.

Does CVE-2026-64746 require authentication?

No. The vulnerability is an authorization bypass that allows an app on the device to add contacts without user authorization.

References