• PATCH AVAILABLE

CVE-2026-64762: out-of-bounds read in Apple iOS and iPadOS

A malicious or buggy app can trigger an out-of-bounds read that may cause unexpected system termination on Apple iOS, iPadOS and macOS devices. CVE-2026-64762 is an out-of-bounds read (CWE-125) fixed by improved bounds checking; affected releases include iOS and iPadOS 18.x before 18.7.10 and macOS releases before 14.8.8, 15.7.8, and 26.6. An attacker only needs to run a crafted app or code on the target device to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00605
CWE
CWE-125
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: install the vendor fixes as soon as possible — Apple released updates that fix the bug in iOS/iPadOS 18.7.10 and macOS 14.8.8, 15.7.8, and 26.6. The strongest fact: vendor-supplied fixes are available for the listed branches.

What is CVE-2026-64762?

A malicious or buggy app can trigger an out-of-bounds read that may cause unexpected system termination on Apple iOS, iPadOS and macOS devices. CVE-2026-64762 is an out-of-bounds read (CWE-125) fixed by improved bounds checking; affected releases include iOS and iPadOS 18.x before 18.7.10 and macOS releases before 14.8.8, 15.7.8, and 26.6. An attacker only needs to run a crafted app or code on the target device to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 18.xbefore 18.7.1018.7.10
macOS 14.xbefore 14.8.814.8.8
macOS 15.xbefore 15.7.815.7.8
macOS 26.xbefore 26.626.6

Is CVE-2026-64762 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-64762

  1. Install the vendor updates: iOS/iPadOS 18.7.10 and macOS 14.8.8, 15.7.8, or 26.6 where applicable.
  2. Prevent untrusted apps from running by restricting app sideloading and enforcing app store / MDM controls.
  3. Monitor endpoint logs for crashes or unusual process terminations and investigate any abnormal app behavior.
  4. Follow Apple’s guidance for updating devices and deploy the updates through your patch management or MDM system.

Frequently asked questions

Is CVE-2026-64762 being actively exploited?

There are no public reports of active exploitation of CVE-2026-64762 as of 2026-09-29.

Which iOS and macOS versions are affected by CVE-2026-64762?

iOS and iPadOS 18.x before 18.7.10 are affected; macOS releases before 14.8.8, 15.7.8, and 26.6 are also affected.

Is there a patch for CVE-2026-64762?

Yes. Apple issued fixes in iOS/iPadOS 18.7.10 and in macOS 14.8.8, 15.7.8, and 26.6.

Does CVE-2026-64762 require authentication?

No authentication is required beyond running code on the device; the issue can be triggered by a crafted app on the target iOS, iPadOS, or macOS system.

References