• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-64747: buffer overflow, local code execution in Apple iOS and iPadOS

Local attackers can trigger a buffer overflow to run arbitrary code in the kernel on Apple iOS and iPadOS devices, tracked as CVE-2026-64747. The bug affects iOS and iPadOS releases before 18.7.10 and before 26.6; related fixes are also available for macOS, tvOS, visionOS and watchOS branches listed by the vendor. Exploitation requires local access to the device and user interaction to trigger the flaw; a successful exploit may yield arbitrary code execution with kernel privileges.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00194
CWE
CWE-120
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so update affected Apple platforms immediately to the fixed releases listed by the vendor to prevent local, user‑initiated kernel compromise.

What is CVE-2026-64747?

Local attackers can trigger a buffer overflow to run arbitrary code in the kernel on Apple iOS and iPadOS devices, tracked as CVE-2026-64747. The bug affects iOS and iPadOS releases before 18.7.10 and before 26.6; related fixes are also available for macOS, tvOS, visionOS and watchOS branches listed by the vendor. Exploitation requires local access to the device and user interaction to trigger the flaw; a successful exploit may yield arbitrary code execution with kernel privileges.

Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
iOS and iPadOS 26.xbefore 26.626.6
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64747 being exploited?

Public exploit code is available.

How to fix CVE-2026-64747

  1. Install vendor updates: iOS/iPadOS 18.7.10 or later and 26.6 or later; update macOS, tvOS, visionOS, and watchOS to the fixed releases listed by Apple.
  2. Restrict local access to sensitive devices and disable unnecessary local services to reduce exposure.
  3. Require device locking and strong authentication to limit opportunities for user‑initiated exploitation.
  4. Monitor endpoint logs for suspicious local activity and block or investigate devices showing signs of compromise.

Frequently asked questions

Is CVE-2026-64747 being actively exploited?

Public exploit code exists for CVE-2026-64747, increasing the risk of real‑world attacks against vulnerable devices.

Which iOS and iPadOS versions are affected by CVE-2026-64747?

iOS and iPadOS releases before 18.7.10 and before 26.6 are listed as affected by CVE-2026-64747.

Is there a patch for CVE-2026-64747?

Yes; Apple released fixes including iOS and iPadOS 18.7.10 and 26.6, and corresponding updates for macOS, tvOS, visionOS, and watchOS.

Does CVE-2026-64747 require authentication?

Exploitation requires local access and user interaction rather than prior authentication on the device.

References