• PATCH AVAILABLE

CVE-2026-64751: pre-auth remote code execution in Apple iOS and iPadOS

Remote attackers can execute arbitrary code on Apple operating systems by exploiting a use-after-free bug that can allow unexpected system termination or kernel memory writes. CVE-2026-64751 affects iOS and iPadOS 26.x before 26.6; macOS 26.x, tvOS 26.x, visionOS 26.x, and watchOS 26.x before 26.6 are also listed as affected. The vulnerability is reachable over the network and requires no privileges or user interaction to exploit.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00588
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — apply Apple’s 26.6 updates immediately because the flaw permits remote code execution without authentication or user interaction, allowing attackers to reach kernel memory from network access.

What is CVE-2026-64751?

Remote attackers can execute arbitrary code on Apple operating systems by exploiting a use-after-free bug that can allow unexpected system termination or kernel memory writes. CVE-2026-64751 affects iOS and iPadOS 26.x before 26.6; macOS 26.x, tvOS 26.x, visionOS 26.x, and watchOS 26.x before 26.6 are also listed as affected. The vulnerability is reachable over the network and requires no privileges or user interaction to exploit. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.626.6
macOS 26.xbefore 26.626.6
tvOS 26.xbefore 26.626.6
visionOS 26.xbefore 26.626.6
watchOS 26.xbefore 26.626.6

Is CVE-2026-64751 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64751

  1. Upgrade affected devices to version 26.6 (iOS/iPadOS/macOS/tvOS/visionOS/watchOS 26.6).
  2. Restrict network exposure of devices until updates are applied, especially services reachable from the internet.
  3. Monitor device and network logs for unusual crashes or kernel-level anomalies.
  4. Follow Apple’s security guidance and deploy updates across managed device fleets promptly.

Frequently asked questions

Is CVE-2026-64751 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which iOS and iPadOS versions are affected by CVE-2026-64751?

iOS and iPadOS 26.x before 26.6 are affected; macOS, tvOS, visionOS and watchOS 26.x before 26.6 are also listed as affected.

Is there a patch for CVE-2026-64751?

Yes. Apple fixed the issue in version 26.6 for iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Does CVE-2026-64751 require authentication?

No. The vulnerability can be triggered remotely without any privileges or user interaction.

References