DIRAS TAKE
Urgent: install the vendor fixes as soon as possible — Apple released updates that fix the bug in iOS/iPadOS 18.7.10 and macOS 14.8.8, 15.7.8, and 26.6. The strongest fact: vendor-supplied fixes are available for the listed branches.
What is CVE-2026-64762?
A malicious or buggy app can trigger an out-of-bounds read that may cause unexpected system termination on Apple iOS, iPadOS and macOS devices. CVE-2026-64762 is an out-of-bounds read (CWE-125) fixed by improved bounds checking; affected releases include iOS and iPadOS 18.x before 18.7.10 and macOS releases before 14.8.8, 15.7.8, and 26.6. An attacker only needs to run a crafted app or code on the target device to exploit the flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| macOS 14.x | before 14.8.8 | 14.8.8 |
| macOS 15.x | before 15.7.8 | 15.7.8 |
| macOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64762 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64762
- Install the vendor updates: iOS/iPadOS 18.7.10 and macOS 14.8.8, 15.7.8, or 26.6 where applicable.
- Prevent untrusted apps from running by restricting app sideloading and enforcing app store / MDM controls.
- Monitor endpoint logs for crashes or unusual process terminations and investigate any abnormal app behavior.
- Follow Apple’s guidance for updating devices and deploy the updates through your patch management or MDM system.
Frequently asked questions
Is CVE-2026-64762 being actively exploited?
There are no public reports of active exploitation of CVE-2026-64762 as of 2026-09-29.
Which iOS and macOS versions are affected by CVE-2026-64762?
iOS and iPadOS 18.x before 18.7.10 are affected; macOS releases before 14.8.8, 15.7.8, and 26.6 are also affected.
Is there a patch for CVE-2026-64762?
Yes. Apple issued fixes in iOS/iPadOS 18.7.10 and in macOS 14.8.8, 15.7.8, and 26.6.
Does CVE-2026-64762 require authentication?
No authentication is required beyond running code on the device; the issue can be triggered by a crafted app on the target iOS, iPadOS, or macOS system.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64762
- cve.org/CVERecord?id=CVE-2026-64762
- support.apple.com/en-us/128067
- support.apple.com/en-us/128071
- support.apple.com/en-us/128072
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026