DIRAS TAKE
Urgent — apply Apple’s 26.6 updates immediately because the flaw permits remote code execution without authentication or user interaction, allowing attackers to reach kernel memory from network access.
What is CVE-2026-64751?
Remote attackers can execute arbitrary code on Apple operating systems by exploiting a use-after-free bug that can allow unexpected system termination or kernel memory writes. CVE-2026-64751 affects iOS and iPadOS 26.x before 26.6; macOS 26.x, tvOS 26.x, visionOS 26.x, and watchOS 26.x before 26.6 are also listed as affected. The vulnerability is reachable over the network and requires no privileges or user interaction to exploit. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64751 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64751
- Upgrade affected devices to version 26.6 (iOS/iPadOS/macOS/tvOS/visionOS/watchOS 26.6).
- Restrict network exposure of devices until updates are applied, especially services reachable from the internet.
- Monitor device and network logs for unusual crashes or kernel-level anomalies.
- Follow Apple’s security guidance and deploy updates across managed device fleets promptly.
Frequently asked questions
Is CVE-2026-64751 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64751?
iOS and iPadOS 26.x before 26.6 are affected; macOS, tvOS, visionOS and watchOS 26.x before 26.6 are also listed as affected.
Is there a patch for CVE-2026-64751?
Yes. Apple fixed the issue in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS and watchOS.
Does CVE-2026-64751 require authentication?
No. The vulnerability can be triggered remotely without any privileges or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64751
- cve.org/CVERecord?id=CVE-2026-64751
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- All Apple CVEs on CVE Radar
- CVEs published in September 2026